Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Debian 11 Bullseye Advisory DLA-4019-1: busybox update critical threats

debian lts
Calendar Grey January 19, 2025
Dist Debian Esm H88
Debian LTS Advisory DLA-4020-1 highlights several vulnerabilities in the curl package. It is advised to upgrade for enhanced protection.
Multiple vulnerabilities have been found in BusyBox, a lightweight single-executable containing various Unix utilities, which potentially allow attackers to cause denial of service...

Summary

CVE-2021-28831

decompress_gunzip.c in BusyBox through 1.32.1 mishandles the error bit
on the huft_build result pointer, with a resultant invalid free or
segmentation fault, via malformed gzip data.

CVE-2021-42374

An out-of-bounds heap read in Busybox's unlzma applet leads to
information leak and denial of service when crafted LZMA-compressed
input is decompressed. This can be triggered by any applet/format that

CVE-2021-42378

A use-after-free in Busybox's awk applet leads to denial of service and
possibly code execution when processing a crafted awk pattern in the
getvar_i function

CVE-2021-42379

A use-after-free in Busybox's awk applet leads to denial of service and
possibly code execution when processing a crafted awk pattern in the
next_input_file function

CVE-2021-42380

A use-after-free in Busybox's awk applet leads to denial of service and
possibly code execution when processing a crafted awk pattern in the
clrvar function

CVE-2021-42381

Read the Full Advisory


Severity
critical
Lowest
Low
Medium
High
Critical

Package: busybox
Version: 1:1.30.1-6+deb11u1
CVE ID: CVE-2021-28831 CVE-2021-42374 CVE-2021-42378 CVE-2021-42379
Debian Bug: 985674 999567 1059049 1059051 1059052

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here