CLSA-2021-1638804058
Dashboard / Vulnerabilities / CLSA-2021-1638804058
CLSA-2021-1638804058
Summary: Fix CVE(s): CVE-2021-42379, CVE-2021-42378, CVE-2021-42380, CVE-2021-42381, CVE-2021-42382, CVE-2021-42383, CVE-2021-42384, CVE-2021-42385, CVE-2021-42386
Details: * SECURITY UPDATE: use-after-free in concat op - debian/patches/CVE-awk-use-after-free.patch: second reference to a field reallocs/moves Fields[] array, but first ref still tries to use the element where it was before move. - CVE-2021-42378 - CVE-2021-42379 - CVE-2021-42380 - CVE-2021-42381 - CVE-2021-42382 - CVE-2021-42383 - CVE-2021-42384 - CVE-2021-42385 - CVE-2021-42386 - debian/patches/CVE-awk-printf-buffer-overflow.patch: printf buffer overflow. - No CVE assigned (but mentioned by upstream maintainer as important at http://lists.busybox.net/pipermail/busybox/2021-November/089328.html).
Affected packages
Package
Name: busybox
Purl: pkg:deb/tuxcare/busybox?distro=ubuntu-16.04
Affected ranges
Type: ECOSYSTEM
Events:
