SUSE-SU-2022:4371-1
Dashboard / Vulnerabilities / SUSE-SU-2022:4371-1
SUSE-SU-2022:4371-1
Summary: Security update for busybox
Details: This update for busybox fixes the following issues: - CVE-2022-30065: Fixed use-after-free in the AWK applet (bsc#1199744). - CVE-2014-9645: Fixed loading of unwanted module with / in module names (bsc#914660). - Update to 1.35.0 also introduced: - awk: fix printf %%, fix read beyond end of buffer - chrt: silence analyzer warning - libarchive: remove duplicate forward declaration - mount: 'mount -o rw ....' should not fall back to RO mount - ps: fix -o pid=PID,args interpreting entire 'PID,args' as header - tar: prevent malicious archives with long name sizes causing OOM - udhcpc6: fix udhcp_find_option to actually find DHCP6 options - xxd: fix -p -r - support for new optoins added to basename, cpio, date, find, mktemp, wget and others
References: https://www.suse.com/support/update/announcement/2022/suse-su-20224371-1/, https://bugzilla.suse.com/1199744, https://bugzilla.suse.com/914660, https://www.suse.com/security/cve/CVE-2014-9645, https://www.suse.com/security/cve/CVE-2022-30065
Affected packages
Package
Name: busybox
Purl: pkg:rpm/suse/busybox&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP4
Affected ranges
Type: ECOSYSTEM
Events:
