Security
Headlines
HeadlinesLatestCVEs

Headline

Ubuntu Security Notice USN-5179-2

Ubuntu Security Notice 5179-2 - USN-5179-1 fixed vulnerabilities in BusyBox. This update provides the corresponding updates for Ubuntu 16.04 ESM. It was discovered that BusyBox incorrectly handled certain malformed gzip archives. If a user or automated system were tricked into processing a specially crafted gzip archive, a remote attacker could use this issue to cause BusyBox to crash, resulting in a denial of service, or possibly execute arbitrary code.

Packet Storm
#vulnerability#ubuntu#dos
==========================================================================Ubuntu Security Notice USN-5179-2May 10, 2022busybox vulnerability==========================================================================A security issue affects these releases of Ubuntu and its derivatives:- Ubuntu 16.04 ESMSummary:BusyBox could be made to crash or run programs if it received speciallycrafted input.Software Description:- busybox: Tiny utilities for small and embedded systemsDetails:USN-5179-1 fixed vulnerabilities in BusyBox. This update provides thecorresponding updates for Ubuntu 16.04 ESM.Original advisory details:  It was discovered that BusyBox incorrectly handled certain malformed gzip  archives. If a user or automated system were tricked into processing a  specially crafted gzip archive, a remote attacker could use this issue to  cause BusyBox to crash, resulting in a denial of service, or possibly  execute arbitrary code. (CVE-2021-28831)Update instructions:The problem can be corrected by updating your system to the followingpackage versions:Ubuntu 16.04 ESM:   busybox                         1:1.22.0-15ubuntu1.4+esm1   busybox-initramfs               1:1.22.0-15ubuntu1.4+esm1   busybox-static                  1:1.22.0-15ubuntu1.4+esm1In general, a standard system update will make all the necessary changes.References:   https://ubuntu.com/security/notices/USN-5179-2   https://ubuntu.com/security/notices/USN-5179-1   CVE-2021-28831

Related news

Ubuntu Security Notice USN-6335-1

Ubuntu Security Notice 6335-1 - It was discovered that BusyBox incorrectly handled certain malformed gzip archives. If a user or automated system were tricked into processing a specially crafted gzip archive, a remote attacker could use this issue to cause BusyBox to crash, resulting in a denial of service, or execute arbitrary code. This issue only affected Ubuntu 14.04 LTS. It was discovered that BusyBox did not properly validate user input when performing certain arithmetic operations. If a user or automated system were tricked into processing a specially crafted file, an attacker could possibly use this issue to cause BusyBox to crash, resulting in a denial of service, or execute arbitrary code.

Scanvus now supports Vulners and Vulns.io VM Linux vulnerability detection APIs

Hello everyone! Great news for my open source Scanvus project! You can now perform vulnerability checks on Linux hosts and docker images not only using the Vulners.com API, but also with the Vulns.io VM API. It’s especially nice that all the code to support the new API was written and contributed by colleagues from Vulns.io. […]

CVE-2021-28831

decompress_gunzip.c in BusyBox through 1.32.1 mishandles the error bit on the huft_build result pointer, with a resultant invalid free or segmentation fault, via malformed gzip data.

Packet Storm: Latest News

Zeek 6.0.8