SUSE-SU-2021:3531-1
Dashboard / Vulnerabilities / SUSE-SU-2021:3531-1
SUSE-SU-2021:3531-1
Summary: Security update for busybox
Details: This update for busybox fixes the following issues: - CVE-2021-28831: Fixed invalid free or segmentation fault via malformed gzip data (bsc#1184522). - CVE-2018-20679: Fixed out of bounds read in udhcp (bsc#1121426). - CVE-2018-1000517: Fixed buffer overflow in the retrieve_file_data() (bsc#1099260). - CVE-2011-5325: Fixed a directory traversal related to 'tar' command (bsc#951562). - CVE-2018-1000500: Fixed missing SSL certificate validation related to the 'wget' command (bsc#1099263).
References: https://www.suse.com/support/update/announcement/2021/suse-su-20213531-1/, https://bugzilla.suse.com/1099260, https://bugzilla.suse.com/1099263, https://bugzilla.suse.com/1121426, https://bugzilla.suse.com/1184522, https://bugzilla.suse.com/951562, https://www.suse.com/security/cve/CVE-2011-5325, https://www.suse.com/security/cve/CVE-2018-1000500, https://www.suse.com/security/cve/CVE-2018-1000517, https://www.suse.com/security/cve/CVE-2018-20679, https://www.suse.com/security/cve/CVE-2021-28831
Affected packages
Package
Name: busybox
Purl: pkg:rpm/suse/busybox&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP2
Affected ranges
Type: ECOSYSTEM
Events:
