CVE-2021-42374
published 2021-11-15CVE-2021-42374: An out-of-bounds heap read in Busybox's unlzma applet leads to information leak and denial of service when crafted LZMA-compressed input is decompressed. This…
PriorityP421medium5.3CVSS 3.1
AVLACHPRLUINSUCLINAH
EPSS
0.58%
43.9th percentile
An out-of-bounds heap read in Busybox's unlzma applet leads to information leak and denial of service when crafted LZMA-compressed input is decompressed. This can be triggered by any applet/format that
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| busybox | busybox | >= 0 < 1:1.30.1-6+deb11u1 | 1:1.30.1-6+deb11u1 |
| busybox | busybox | >= 0 < 1:1.35.0-1 | 1:1.35.0-1 |
| busybox | busybox | >= 0 < 1:1.35.0-1 | 1:1.35.0-1 |
| busybox | busybox | >= 0 < 1:1.35.0-1 | 1:1.35.0-1 |
| busybox | busybox | >= 0 < 1:1.27.2-2ubuntu3.4 | 1:1.27.2-2ubuntu3.4 |
| busybox | busybox | >= 0 < 1:1.30.1-4ubuntu6.4 | 1:1.30.1-4ubuntu6.4 |
| busybox | busybox | 1.27.0 – 1.33.1 | — |
| busybox | busybox | >= unspecified < 1.34.0 | 1.34.0 |
| debian | busybox | < busybox 1:1.35.0-1 (bookworm) | busybox 1:1.35.0-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| msrc | azl3_busybox_1.35.1-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_busybox_1.36.1-12_on_azure_linux_3.0 | — | — |
| msrc | cbl2_busybox_1.35.0-1_on_cbl_mariner_2.0 | — | — |
| msrc | cm1_busybox_1.34.1-1_on_cbl_mariner_1.0 | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H
nvdv2.03.3LOWAV:L/AC:M/Au:N/C:P/I:N/A:P
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_debian5.3LOW
vendor_msrc5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens SIMATIC S7-1500 TM MFP BIOS
cisa_ics·2023-06-15·CVSS 5.9
[MEDIUM] Siemens SIMATIC S7-1500 TM MFP BIOS
ICS Advisory
##
Siemens SIMATIC S7-1500 TM MFP BIOS
Release DateJune 15, 2023
Alert CodeICSA-23-166-10
## As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely / low attack complexity
- Vendor: Siemens
- Equipment: SIMATIC S7-1500 TM MFP
- Vulnerabilities: Improper Input Validation, Out-of-bounds Read, Use After Free, Out-of-bounds Write, Infinite Loop, Reachable Assertion, Off-by-one Error, Incorrect Default Permissions, Double Fr
CISA ICS
Siemens SINAMICS Medium Voltage Products
cisa_ics·2023-06-15·CVSS 7.5
[HIGH] Siemens SINAMICS Medium Voltage Products
ICS Advisory
##
Siemens SINAMICS Medium Voltage Products
Release DateJune 15, 2023
Alert CodeICSA-23-166-12
## As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely / low attack complexity
- Vendor: Siemens
- Equipment: SINAMICS MV (medium voltage) products
- Vulnerabilities: Out-of-bounds Write, Out-of-bounds Read, Use After Free, Improper Authentication, OS Command Injection, Improper Certificate Validation, Improper Res
CISA ICS
Siemens SCALANCE Third-Party
cisa_ics·2023-03-21
Siemens SCALANCE Third-Party
ICS Advisory
##
Siemens SCALANCE Third-Party
Release DateMarch 21, 2023
Alert CodeICSA-23-080-07
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
## 1. EXECUTIVE SUMMARY
- CVSS v3 8.1
- ATTENTION: Exploitable remotely
- Vendor: Siemens
- Equipment: Various third-party components used in SCALANCE W-700 devices
- Vulnerabilities: Generation of Error Message Containing Sensitive Information, Out-of-bounds Write, NULL Pointer Dereference, Out-of-bounds Read, Improper Input Validation, Release of Inval
CISA ICS
Siemens SCALANCE, RUGGEDCOM Third-Party
cisa_ics·2023-03-16
Siemens SCALANCE, RUGGEDCOM Third-Party
ICS Advisory
##
Siemens SCALANCE, RUGGEDCOM Third-Party
Release DateMarch 16, 2023
Alert CodeICSA-23-075-01
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/Low attack complexity
- Vendor: Siemens
- Equipment: Busybox Applet affecting SCALANCE and RUGGEDCOM products
- Vulnerabilities: Out-of-bounds Write, Exposure of Sensitive Information to an Unauthorized Actor, Improper Locking, Improper Input Validation, NULL Pointer Deref
Ubuntu
BusyBox vulnerabilities
vendor_ubuntu·2021-12-07·CVSS 7.5
CVE-2021-28831 [HIGH] BusyBox vulnerabilities
Title: BusyBox vulnerabilities
Summary: Several security issues were fixed in BusyBox.
It was discovered that BusyBox incorrectly handled certain malformed gzip
archives. If a user or automated system were tricked into processing a
specially crafted gzip archive, a remote attacker could use this issue to
cause BusyBox to crash, resulting in a denial of service, or possibly
execute arbitrary code. (CVE-2021-28831)
It was discovered that BusyBox incorrectly handled certain malformed LZMA
archives. If a user or automated system were tricked into processing a
specially crafted LZMA archive, a remote attacker could use this issue to
cause BusyBox to crash, resulting in a denial of service, or possibly
leak sensitive information. (CVE-2021-42374)
Vera Mens, Uri Katz, Tal Keren, Sharon Brizin
Red Hat
busybox: out-of-bounds read in unlzma applet leads to information leak and denial of service when crafted LZMA-compressed input is decompressed
vendor_redhat·2021-11-09·CVSS 5.3
CVE-2021-42374 [MEDIUM] CWE-125 busybox: out-of-bounds read in unlzma applet leads to information leak and denial of service when crafted LZMA-compressed input is decompressed
busybox: out-of-bounds read in unlzma applet leads to information leak and denial of service when crafted LZMA-compressed input is decompressed
An out-of-bounds heap read in Busybox's unlzma applet leads to information leak and denial of service when crafted LZMA-compressed input is decompressed. This can be triggered by any applet/format that
A flaw was found in BusyBox. It did not properly sanitize while crafted LZMA compressed input was decompressing, leading to a denial of service. The highest threat from this vulnerability is to confidentiality and system availability.
Package: busybox (Red Hat Enterprise Linux 6) - Not affected
Microsoft
An out-of-bounds heap read in Busybox's unlzma applet leads to information leak and denial of service when crafted LZMA-compressed input is decompressed. This can be triggered by any applet/format tha
vendor_msrc·2021-11-09·CVSS 5.3
CVE-2021-42374 [MEDIUM] CWE-125 An out-of-bounds heap read in Busybox's unlzma applet leads to information leak and denial of service when crafted LZMA-compressed input is decompressed. This can be triggered by any applet/format tha
An out-of-bounds heap read in Busybox's unlzma applet leads to information leak and denial of service when crafted LZMA-compressed input is decompressed. This can be triggered by any applet/format that
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update th
Debian
CVE-2021-42374: busybox - An out-of-bounds heap read in Busybox's unlzma applet leads to information leak ...
vendor_debian·2021·CVSS 5.3
CVE-2021-42374 [MEDIUM] CVE-2021-42374: busybox - An out-of-bounds heap read in Busybox's unlzma applet leads to information leak ...
An out-of-bounds heap read in Busybox's unlzma applet leads to information leak and denial of service when crafted LZMA-compressed input is decompressed. This can be triggered by any applet/format that
Scope: local
bookworm: resolved (fixed in 1:1.35.0-1)
bullseye: resolved (fixed in 1:1.30.1-6+deb11u1)
forky: resolved (fixed in 1:1.35.0-1)
sid: resolved (fixed in 1:1.35.0-1)
trixie: resolved (fixed in 1:1.35.0-1)
GHSA
GHSA-6f92-r9cq-v6cq: An out-of-bounds heap read in Busybox's unlzma applet leads to information leak and denial of service when crafted LZMA-compressed input is decompress
ghsa_unreviewed·2022-05-24
CVE-2021-42374 [CRITICAL] CWE-125 GHSA-6f92-r9cq-v6cq: An out-of-bounds heap read in Busybox's unlzma applet leads to information leak and denial of service when crafted LZMA-compressed input is decompress
An out-of-bounds heap read in Busybox's unlzma applet leads to information leak and denial of service when crafted LZMA-compressed input is decompressed. This can be triggered by any applet/format that
OSV
busybox vulnerabilities
osv·2021-12-07·CVSS 7.5
CVE-2021-28831 [HIGH] busybox vulnerabilities
busybox vulnerabilities
It was discovered that BusyBox incorrectly handled certain malformed gzip
archives. If a user or automated system were tricked into processing a
specially crafted gzip archive, a remote attacker could use this issue to
cause BusyBox to crash, resulting in a denial of service, or possibly
execute arbitrary code. (CVE-2021-28831)
It was discovered that BusyBox incorrectly handled certain malformed LZMA
archives. If a user or automated system were tricked into processing a
specially crafted LZMA archive, a remote attacker could use this issue to
cause BusyBox to crash, resulting in a denial of service, or possibly
leak sensitive information. (CVE-2021-42374)
Vera Mens, Uri Katz, Tal Keren, Sharon Brizinov, and Shachar Menashe
discovered that BusyBox incorrectly hand
OSV
CVE-2021-42374: An out-of-bounds heap read in Busybox's unlzma applet leads to information leak and denial of service when crafted LZMA-compressed input is decompress
osv·2021-11-15·CVSS 5.3
CVE-2021-42374 [MEDIUM] CVE-2021-42374: An out-of-bounds heap read in Busybox's unlzma applet leads to information leak and denial of service when crafted LZMA-compressed input is decompress
An out-of-bounds heap read in Busybox's unlzma applet leads to information leak and denial of service when crafted LZMA-compressed input is decompressed. This can be triggered by any applet/format that
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://claroty.com/team82/research/unboxing-busybox-14-vulnerabilities-uncovered-by-claroty-jfroghttps://jfrog.com/blog/unboxing-busybox-14-new-vulnerabilities-uncovered-by-claroty-and-jfrog/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6T2TURBYYJGBMQTTN2DSOAIQGP7WCPGV/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UQXGOGWBIYWOIVXJVRKHZR34UMEHQBXS/https://security.netapp.com/advisory/ntap-20211223-0002/https://claroty.com/team82/research/unboxing-busybox-14-vulnerabilities-uncovered-by-claroty-jfroghttps://jfrog.com/blog/unboxing-busybox-14-new-vulnerabilities-uncovered-by-claroty-and-jfrog/https://lists.debian.org/debian-lts-announce/2025/01/msg00012.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6T2TURBYYJGBMQTTN2DSOAIQGP7WCPGV/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UQXGOGWBIYWOIVXJVRKHZR34UMEHQBXS/https://security.netapp.com/advisory/ntap-20211223-0002/
2021-11-15
Published