CVE-2021-42373
published 2021-11-15CVE-2021-42373: A NULL pointer dereference in Busybox's man applet leads to denial of service when a section name is supplied but no page argument is given
PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.38%
30.0th percentile
A NULL pointer dereference in Busybox's man applet leads to denial of service when a section name is supplied but no page argument is given
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| busybox | busybox | — | — |
| busybox | busybox | — | — |
| busybox | busybox | >= 0 < 1:1.35.0-1 | 1:1.35.0-1 |
| busybox | busybox | >= 0 < 1:1.35.0-1 | 1:1.35.0-1 |
| busybox | busybox | >= 0 < 1:1.35.0-1 | 1:1.35.0-1 |
| busybox | busybox | >= unspecified < 1.34.0 | 1.34.0 |
| debian | busybox | < busybox 1:1.35.0-1 (bookworm) | busybox 1:1.35.0-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
osv5.5MEDIUM
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6w3h-h7gw-72qf: A NULL pointer dereference in Busybox's man applet leads to denial of service when a section name is supplied but no page argument is given
ghsa_unreviewed·2022-05-24
CVE-2021-42373 [HIGH] CWE-476 GHSA-6w3h-h7gw-72qf: A NULL pointer dereference in Busybox's man applet leads to denial of service when a section name is supplied but no page argument is given
A NULL pointer dereference in Busybox's man applet leads to denial of service when a section name is supplied but no page argument is given
OSV
CVE-2021-42373: A NULL pointer dereference in Busybox's man applet leads to denial of service when a section name is supplied but no page argument is given
osv·2021-11-15·CVSS 5.5
CVE-2021-42373 [MEDIUM] CVE-2021-42373: A NULL pointer dereference in Busybox's man applet leads to denial of service when a section name is supplied but no page argument is given
A NULL pointer dereference in Busybox's man applet leads to denial of service when a section name is supplied but no page argument is given
CISA ICS
Siemens SIMATIC S7-1500 TM MFP BIOS
cisa_ics·2023-06-15·CVSS 5.9
[MEDIUM] Siemens SIMATIC S7-1500 TM MFP BIOS
ICS Advisory
##
Siemens SIMATIC S7-1500 TM MFP BIOS
Release DateJune 15, 2023
Alert CodeICSA-23-166-10
## As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely / low attack complexity
- Vendor: Siemens
- Equipment: SIMATIC S7-1500 TM MFP
- Vulnerabilities: Improper Input Validation, Out-of-bounds Read, Use After Free, Out-of-bounds Write, Infinite Loop, Reachable Assertion, Off-by-one Error, Incorrect Default Permissions, Double Fr
CISA ICS
Siemens SCALANCE Third-Party
cisa_ics·2023-03-21
Siemens SCALANCE Third-Party
ICS Advisory
##
Siemens SCALANCE Third-Party
Release DateMarch 21, 2023
Alert CodeICSA-23-080-07
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
## 1. EXECUTIVE SUMMARY
- CVSS v3 8.1
- ATTENTION: Exploitable remotely
- Vendor: Siemens
- Equipment: Various third-party components used in SCALANCE W-700 devices
- Vulnerabilities: Generation of Error Message Containing Sensitive Information, Out-of-bounds Write, NULL Pointer Dereference, Out-of-bounds Read, Improper Input Validation, Release of Inval
CISA ICS
Siemens SCALANCE, RUGGEDCOM Third-Party
cisa_ics·2023-03-16
Siemens SCALANCE, RUGGEDCOM Third-Party
ICS Advisory
##
Siemens SCALANCE, RUGGEDCOM Third-Party
Release DateMarch 16, 2023
Alert CodeICSA-23-075-01
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/Low attack complexity
- Vendor: Siemens
- Equipment: Busybox Applet affecting SCALANCE and RUGGEDCOM products
- Vulnerabilities: Out-of-bounds Write, Exposure of Sensitive Information to an Unauthorized Actor, Improper Locking, Improper Input Validation, NULL Pointer Deref
Red Hat
busybox: NULL pointer dereference in man applet leads to denial of service when a section name is supplied but no page argument is given
vendor_redhat·2021-11-09·CVSS 5.5
CVE-2021-42373 [MEDIUM] CWE-476 busybox: NULL pointer dereference in man applet leads to denial of service when a section name is supplied but no page argument is given
busybox: NULL pointer dereference in man applet leads to denial of service when a section name is supplied but no page argument is given
A NULL pointer dereference in Busybox's man applet leads to denial of service when a section name is supplied but no page argument is given
A flaw was found in BusyBox where it did not properly sanitize certain page arguments, leading to a denial of service. The highest threat from this vulnerability is to system availability.
Package: busybox (Red Hat Enterprise Linux 6) - Not affected
Debian
CVE-2021-42373: busybox - A NULL pointer dereference in Busybox's man applet leads to denial of service wh...
vendor_debian·2021·CVSS 5.5
CVE-2021-42373 [MEDIUM] CVE-2021-42373: busybox - A NULL pointer dereference in Busybox's man applet leads to denial of service wh...
A NULL pointer dereference in Busybox's man applet leads to denial of service when a section name is supplied but no page argument is given
Scope: local
bookworm: resolved (fixed in 1:1.35.0-1)
bullseye: open
forky: resolved (fixed in 1:1.35.0-1)
sid: resolved (fixed in 1:1.35.0-1)
trixie: resolved (fixed in 1:1.35.0-1)
No detection rules found.
No public exploits indexed.
https://claroty.com/team82/research/unboxing-busybox-14-vulnerabilities-uncovered-by-claroty-jfroghttps://jfrog.com/blog/unboxing-busybox-14-new-vulnerabilities-uncovered-by-claroty-and-jfrog/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6T2TURBYYJGBMQTTN2DSOAIQGP7WCPGV/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UQXGOGWBIYWOIVXJVRKHZR34UMEHQBXS/https://security.netapp.com/advisory/ntap-20211223-0002/https://claroty.com/team82/research/unboxing-busybox-14-vulnerabilities-uncovered-by-claroty-jfroghttps://jfrog.com/blog/unboxing-busybox-14-new-vulnerabilities-uncovered-by-claroty-and-jfrog/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6T2TURBYYJGBMQTTN2DSOAIQGP7WCPGV/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UQXGOGWBIYWOIVXJVRKHZR34UMEHQBXS/https://security.netapp.com/advisory/ntap-20211223-0002/
2021-11-15
Published