Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

openSUSE Leap 15.3: 2021-3531-1 Important: Busybox Security Update

opensuse
Calendar Grey October 27, 2021
Dist Opensuse Esm H88
Recent patch resolves several critical vulnerabilities in busybox for openSUSE Leap 15.3, enhancing both performance and protection.
An update that fixes 5 vulnerabilities is now available

Description

This update for busybox fixes the following issues:

- CVE-2021-28831: Fixed invalid free or segmentation fault via malformed

gzip data (bsc#1184522).

- CVE-2018-20679: Fixed out of bounds read in udhcp (bsc#1121426).

- CVE-2018-1000517: Fixed buffer overflow in the retrieve_file_data()

(bsc#1099260).

- CVE-2011-5325: Fixed a directory traversal related to 'tar' command

(bsc#951562).

- CVE-2018-1000500: Fixed missing SSL certificate validation related to

the 'wget' command (bsc#1099263).

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.3:

zypper in -t patch openSUSE-SLE-15.3-2021-3531=1

Package List

- openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64):

busybox-1.26.2-4.5.1

busybox-static-1.26.2-4.5.1

References

https://www.suse.com/security/cve/CVE-2011-5325.html

https://www.suse.com/security/cve/CVE-2018-1000500.html

https://www.suse.com/security/cve/CVE-2018-1000517.html

https://www.suse.com/security/cve/CVE-2018-20679.html

https://www.suse.com/security/cve/CVE-2021-28831.html

https://bugzilla.suse.com/1099260

https://bugzilla.suse.com/1099263

https://bugzilla.suse.com/1121426

https://bugzilla.suse.com/1184522

https://bugzilla.suse.com/951562

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2021:3531-1
Rating: important
Affected Products: openSUSE Leap 15.3 .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here