SB2021040167 - Improper Handling of Exceptional Conditions in busybox (Alpine package)
Published: April 1, 2021 Updated: February 9, 2022
Security Bulletin ID
SB2021040167
Severity
Medium
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Remote access
Highest impact
Denial of service
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper Handling of Exceptional Conditions (CVE-ID: CVE-2021-28831)
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to improper handling of error bit on the huft_build result pointer in decompress_gunzip.c. A remote attacker can pass malformed gzip data to the application, trigger an invalid free and perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=0d639f13e315e43a11821d963031ed5b49b15a15
- https://git.alpinelinux.org/aports/commit/?id=26527b0535f65a4ac0ae7f3c9afb2294885b21cc
- https://git.alpinelinux.org/aports/commit/?id=7332e004b92f2a688a28eee7628a1e6e16d76147
- https://git.alpinelinux.org/aports/commit/?id=7acc3190c16c19db5767c094d5ea6de75bbc2ae8
- https://git.alpinelinux.org/aports/commit/?id=8457a320f13d202a1c65be2652f0d030880f17f0