Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

CVE-2021-42374

Published: 15 November 2021

An out-of-bounds heap read in Busybox's unlzma applet leads to information leak and denial of service when crafted LZMA-compressed input is decompressed. This can be triggered by any applet/format that

Notes

AuthorNote
mdeslaur
introduced in 1.27.0

Priority

Low

Cvss 3 Severity Score

5.3

Score breakdown

Status

Package Release Status
busybox
Launchpad, Ubuntu, Debian
bionic
Released (1:1.27.2-2ubuntu3.4)
focal
Released (1:1.30.1-4ubuntu6.4)
hirsute
Released (1:1.30.1-6ubuntu2.1)
impish
Released (1:1.30.1-6ubuntu3.1)
jammy
Released (1:1.30.1-7ubuntu2)
trusty Not vulnerable

upstream
Released (1.34.0)
xenial Not vulnerable

Patches:
upstream: https://git.busybox.net/busybox/commit/?id=04f052c56ded5ab6a904e3a264a73dc0412b2e78

Severity score breakdown

Parameter Value
Base score 5.3
Attack vector Local
Attack complexity High
Privileges required Low
User interaction None
Scope Unchanged
Confidentiality Low
Integrity impact None
Availability impact High
Vector CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H