MGASA-2021-0009 - Updated busybox packages fix a security vulnerability Publication date: 08 Jan 2021 URL: https://advisories.mageia.org/MGASA-2021-0009.html Type: security Affected Mageia releases: 7 CVE: CVE-2018-1000500 Busybox contains a Missing SSL certificate validation vulnerability in The "busybox wget" applet that can result in arbitrary code execution. This attack appear to be exploitable via Simply download any file over HTTPS using "busybox wget ". (). References: - https://bugs.mageia.org/show_bug.cgi?id=27307 - https://ubuntu.com/security/notices/USN-4531-1 - https://www.cve.org/CVERecord?id=CVE-2018-1000500 SRPMS: - 7/core/busybox-1.30.1-1.1.mga7 . Busybox contains a Missing SSL certificate validation vulnerability in The "busybox wget" applet that can result in arbitrary code execution. This attack appear to be exploitable via Simply download any file over HTTPS using "busybox wget ". (). . The recently patched busybox packages address a vulnerability in SSL certificate verification, mitigating risks associated with possible code execution. Discover further information.. busybox security,mageia update,code execution risk,ssl validation issue. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.