CVE-2015-9261
published 2018-07-26CVE-2015-9261: huft_build in archival/libarchive/decompress_gunzip.c in BusyBox before 1.27.2 misuses a pointer, causing segfaults and an application crash during an unzip…
PriorityP421medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
2.37%
81.9th percentile
huft_build in archival/libarchive/decompress_gunzip.c in BusyBox before 1.27.2 misuses a pointer, causing segfaults and an application crash during an unzip operation on a specially crafted ZIP file.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| busybox | busybox | < 1.27.2 | 1.27.2 |
| busybox | busybox | >= 0 < 1:1.27.2-1 | 1:1.27.2-1 |
| busybox | busybox | >= 0 < 1:1.27.2-1 | 1:1.27.2-1 |
| busybox | busybox | >= 0 < 1:1.27.2-1 | 1:1.27.2-1 |
| busybox | busybox | >= 0 < 1:1.27.2-1 | 1:1.27.2-1 |
| busybox | busybox | >= 0 < 1:1.21.0-1ubuntu1.4 | 1:1.21.0-1ubuntu1.4 |
| busybox | busybox | >= 0 < 1:1.22.0-15ubuntu1.4 | 1:1.22.0-15ubuntu1.4 |
| busybox | busybox | >= 0 < 1:1.27.2-2ubuntu3.2 | 1:1.27.2-2ubuntu3.2 |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | busybox | < busybox 1:1.27.2-1 (bookworm) | busybox 1:1.27.2-1 (bookworm) |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4ph6-v858-6wh9: huft_build in archival/libarchive/decompress_gunzip
ghsa_unreviewed·2022-05-13
CVE-2015-9261 [MEDIUM] CWE-476 GHSA-4ph6-v858-6wh9: huft_build in archival/libarchive/decompress_gunzip
huft_build in archival/libarchive/decompress_gunzip.c in BusyBox before 1.27.2 misuses a pointer, causing segfaults and an application crash during an unzip operation on a specially crafted ZIP file.
OSV
busybox vulnerabilities
osv·2019-04-03·CVSS 7.5
CVE-2011-5325 [HIGH] busybox vulnerabilities
busybox vulnerabilities
Tyler Hicks discovered that BusyBox incorrectly handled symlinks inside tar
archives. If a user or automated system were tricked into processing a
specially crafted tar archive, a remote attacker could overwrite arbitrary
files outside of the current directory. This issue only affected Ubuntu
14.04 LTS and Ubuntu 16.04 LTS. (CVE-2011-5325)
Mathias Krause discovered that BusyBox incorrectly handled kernel module
loading restrictions. A local attacker could possibly use this issue to
bypass intended restrictions. This issue only affected Ubuntu 14.04 LTS.
(CVE-2014-9645)
It was discovered that BusyBox incorrectly handled certain ZIP archives. If
a user or automated system were tricked into processing a specially crafted
ZIP archive, a remote attacker could cause Bu
OSV
CVE-2015-9261: huft_build in archival/libarchive/decompress_gunzip
osv·2018-07-26·CVSS 5.5
CVE-2015-9261 [MEDIUM] CVE-2015-9261: huft_build in archival/libarchive/decompress_gunzip
huft_build in archival/libarchive/decompress_gunzip.c in BusyBox before 1.27.2 misuses a pointer, causing segfaults and an application crash during an unzip operation on a specially crafted ZIP file.
CISA ICS
Advantech Spectre RT Industrial Routers
cisa_ics·2021-02-23·CVSS 7.5
[HIGH] Advantech Spectre RT Industrial Routers
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Advantech Spectre RT Industrial Routers
Last RevisedFebruary 23, 2021
Alert CodeICSA-21-054-03
## 1. EXECUTIVE SUMMARY
- CVSS v3 10.0
- ATTENTION: Exploitable remotely/low skill level to exploit
- Vendor: Advantech
- Equipment: Spectre RT Industrial Routers
- Vulnerabilities: Improper Neutralization of Input During Web Page Generation, Cleartext Transmission of Sensitive Information, Improper Restriction of Excessive Authentication Attempts, Use of a Broken or Risky Cryptographic Algorithm, Use of Platform-Dependent Third-party Components
## 2. RISK EVALUATION
Successful e
Ubuntu
BusyBox vulnerabilities
vendor_ubuntu·2019-04-03·CVSS 7.5
CVE-2011-5325 [HIGH] BusyBox vulnerabilities
Title: BusyBox vulnerabilities
Summary: Several security issues were fixed in BusyBox.
Tyler Hicks discovered that BusyBox incorrectly handled symlinks inside tar
archives. If a user or automated system were tricked into processing a
specially crafted tar archive, a remote attacker could overwrite arbitrary
files outside of the current directory. This issue only affected Ubuntu
14.04 LTS and Ubuntu 16.04 LTS. (CVE-2011-5325)
Mathias Krause discovered that BusyBox incorrectly handled kernel module
loading restrictions. A local attacker could possibly use this issue to
bypass intended restrictions. This issue only affected Ubuntu 14.04 LTS.
(CVE-2014-9645)
It was discovered that BusyBox incorrectly handled certain ZIP archives. If
a user or automated system were tricked into processing a
Red Hat
busybox: Segmentation fault when unzipping specially crafted zip file
vendor_redhat·2015-10-25·CVSS 5.5
CVE-2015-9261 [MEDIUM] CWE-682 busybox: Segmentation fault when unzipping specially crafted zip file
busybox: Segmentation fault when unzipping specially crafted zip file
huft_build in archival/libarchive/decompress_gunzip.c in BusyBox before 1.27.2 misuses a pointer, causing segfaults and an application crash during an unzip operation on a specially crafted ZIP file.
Package: busybox (Red Hat Enterprise Linux 4) - Will not fix
Package: busybox (Red Hat Enterprise Linux 5) - Will not fix
Package: busybox (Red Hat Enterprise Linux 6) - Will not fix
Debian
CVE-2015-9261: busybox - huft_build in archival/libarchive/decompress_gunzip.c in BusyBox before 1.27.2 m...
vendor_debian·2015·CVSS 5.5
CVE-2015-9261 [MEDIUM] CVE-2015-9261: busybox - huft_build in archival/libarchive/decompress_gunzip.c in BusyBox before 1.27.2 m...
huft_build in archival/libarchive/decompress_gunzip.c in BusyBox before 1.27.2 misuses a pointer, causing segfaults and an application crash during an unzip operation on a specially crafted ZIP file.
Scope: local
bookworm: resolved (fixed in 1:1.27.2-1)
bullseye: resolved (fixed in 1:1.27.2-1)
forky: resolved (fixed in 1:1.27.2-1)
sid: resolved (fixed in 1:1.27.2-1)
trixie: resolved (fixed in 1:1.27.2-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-9261 busybox: Segmentation fault when unzipping specially crafted zip file
bugzilla·2015-10-29·CVSS 5.5
CVE-2015-9261 [MEDIUM] CVE-2015-9261 busybox: Segmentation fault when unzipping specially crafted zip file
CVE-2015-9261 busybox: Segmentation fault when unzipping specially crafted zip file
It was found that unziping a specially crafted zip file results in a computation of an invalid pointer and a crash reading an invalid address.
Crash report with reproducer can be found here:
http://seclists.org/oss-sec/2015/q4/158
Discussion:
Created busybox tracking bugs for this issue:
Affects: fedora-all [bug 1276428]
---
Upstream patch:
http://git.busybox.net/busybox/commit/?id=1de25a6e87e0e627aa34298105a3d17c60a1f44e
arXiv
One Bad Apple Spoils the Barrel: Understanding the Security Risks Introduced by Third-Party Components in IoT Firmware
arxiv_fulltext·2022-12-29
One Bad Apple Spoils the Barrel: Understanding the Security Risks Introduced by Third-Party Components in IoT Firmware
One Bad Apple Spoils the Barrel: Understanding the Security Risks Introduced by Third-Party Components in IoT Firmware
## Abstract
Currently, the development of IoT firmware heavily depends on third-party components (TPCs) to improve development efficiency. Nevertheless, TPCs are not secure, and the vulnerabilities in TPCs will influence the security of IoT firmware. Existing works pay less attention to the vulnerabilities caused by TPCs, and we still lack a comprehensive understanding of the security impact of TPC vulnerability against firmware. To fill in the knowledge gap, we design and implement , which leverages syntactical features and control-flow graph features to detect the TPCs in firmware, and then recognizes the corresponding vulnerabilities. Based on , we present the first l
http://packetstormsecurity.com/files/153278/WAGO-852-Industrial-Managed-Switch-Series-Code-Execution-Hardcoded-Credentials.htmlhttp://packetstormsecurity.com/files/154361/Cisco-Device-Hardcoded-Credentials-GNU-glibc-BusyBox.htmlhttp://packetstormsecurity.com/files/167552/Nexans-FTTO-GigaSwitch-Outdated-Components-Hardcoded-Backdoor.htmlhttp://seclists.org/fulldisclosure/2019/Jun/18http://seclists.org/fulldisclosure/2019/Sep/7http://seclists.org/fulldisclosure/2020/Aug/20http://seclists.org/fulldisclosure/2022/Jun/36http://www.openwall.com/lists/oss-security/2015/10/25/3https://bugs.debian.org/803097https://git.busybox.net/busybox/commit/?id=1de25a6e87e0e627aa34298105a3d17c60a1f44ehttps://lists.debian.org/debian-lts-announce/2018/07/msg00037.htmlhttps://lists.debian.org/debian-lts-announce/2021/02/msg00020.htmlhttps://seclists.org/bugtraq/2019/Jun/14https://seclists.org/bugtraq/2019/Sep/7https://usn.ubuntu.com/3935-1/http://packetstormsecurity.com/files/153278/WAGO-852-Industrial-Managed-Switch-Series-Code-Execution-Hardcoded-Credentials.htmlhttp://packetstormsecurity.com/files/154361/Cisco-Device-Hardcoded-Credentials-GNU-glibc-BusyBox.htmlhttp://packetstormsecurity.com/files/167552/Nexans-FTTO-GigaSwitch-Outdated-Components-Hardcoded-Backdoor.htmlhttp://seclists.org/fulldisclosure/2019/Jun/18http://seclists.org/fulldisclosure/2019/Sep/7http://seclists.org/fulldisclosure/2020/Aug/20http://seclists.org/fulldisclosure/2022/Jun/36http://www.openwall.com/lists/oss-security/2015/10/25/3https://bugs.debian.org/803097https://git.busybox.net/busybox/commit/?id=1de25a6e87e0e627aa34298105a3d17c60a1f44ehttps://lists.debian.org/debian-lts-announce/2018/07/msg00037.htmlhttps://lists.debian.org/debian-lts-announce/2021/02/msg00020.htmlhttps://seclists.org/bugtraq/2019/Jun/14https://seclists.org/bugtraq/2019/Sep/7https://usn.ubuntu.com/3935-1/
2018-07-26
Published