Advisory ID: SUSE-SU-2022:4371-1 Released: Thu Dec 8 17:19:43 2022 Summary: Security update for busybox Type: security Severity: moderate
References : 1199744 914660 CVE-2014-9645 CVE-2022-30065
1199744,914660,CVE-2014-9645,CVE-2022-30065
This update for busybox fixes the following issues:
- CVE-2022-30065: Fixed use-after-free in the AWK applet (bsc#1199744).
- CVE-2014-9645: Fixed loading of unwanted module with / in module names (bsc#914660).
- Update to 1.35.0 also introduced:
- awk: fix printf %%, fix read beyond end of buffer
- chrt: silence analyzer warning
- libarchive: remove duplicate forward declaration
- mount: 'mount -o rw ....' should not fall back to RO mount
- ps: fix -o pid=PID,args interpreting entire 'PID,args' as header
- tar: prevent malicious archives with long name sizes causing OOM
- udhcpc6: fix udhcp_find_option to actually find DHCP6 options
- xxd: fix -p -r
- support for new optoins added to basename, cpio, date, find,
Get the latest Linux and open source security news straight to your inbox.