CVE-2021-42375
published 2021-11-15CVE-2021-42375: An incorrect handling of a special element in Busybox's ash applet leads to denial of service when processing a crafted shell command, due to the shell…
PriorityP421medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.38%
30.1th percentile
An incorrect handling of a special element in Busybox's ash applet leads to denial of service when processing a crafted shell command, due to the shell mistaking specific characters for reserved characters. This may be used for DoS under rare conditions of filtered command input.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| busybox | busybox | — | — |
| busybox | busybox | >= 0 < 1:1.35.0-1 | 1:1.35.0-1 |
| busybox | busybox | >= 0 < 1:1.35.0-1 | 1:1.35.0-1 |
| busybox | busybox | >= 0 < 1:1.35.0-1 | 1:1.35.0-1 |
| busybox | busybox | >= unspecified < 1.34.0 | 1.34.0 |
| debian | busybox | < busybox 1:1.35.0-1 (bookworm) | busybox 1:1.35.0-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.01.9LOWAV:L/AC:M/Au:N/C:N/I:N/A:P
osv5.5MEDIUM
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens SIMATIC S7-1500 TM MFP BIOS
cisa_ics·2023-06-15·CVSS 5.9
[MEDIUM] Siemens SIMATIC S7-1500 TM MFP BIOS
ICS Advisory
##
Siemens SIMATIC S7-1500 TM MFP BIOS
Release DateJune 15, 2023
Alert CodeICSA-23-166-10
## As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely / low attack complexity
- Vendor: Siemens
- Equipment: SIMATIC S7-1500 TM MFP
- Vulnerabilities: Improper Input Validation, Out-of-bounds Read, Use After Free, Out-of-bounds Write, Infinite Loop, Reachable Assertion, Off-by-one Error, Incorrect Default Permissions, Double Fr
CISA ICS
Siemens SCALANCE Third-Party
cisa_ics·2023-03-21
Siemens SCALANCE Third-Party
ICS Advisory
##
Siemens SCALANCE Third-Party
Release DateMarch 21, 2023
Alert CodeICSA-23-080-07
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
## 1. EXECUTIVE SUMMARY
- CVSS v3 8.1
- ATTENTION: Exploitable remotely
- Vendor: Siemens
- Equipment: Various third-party components used in SCALANCE W-700 devices
- Vulnerabilities: Generation of Error Message Containing Sensitive Information, Out-of-bounds Write, NULL Pointer Dereference, Out-of-bounds Read, Improper Input Validation, Release of Inval
CISA ICS
Siemens SCALANCE, RUGGEDCOM Third-Party
cisa_ics·2023-03-16
Siemens SCALANCE, RUGGEDCOM Third-Party
ICS Advisory
##
Siemens SCALANCE, RUGGEDCOM Third-Party
Release DateMarch 16, 2023
Alert CodeICSA-23-075-01
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/Low attack complexity
- Vendor: Siemens
- Equipment: Busybox Applet affecting SCALANCE and RUGGEDCOM products
- Vulnerabilities: Out-of-bounds Write, Exposure of Sensitive Information to an Unauthorized Actor, Improper Locking, Improper Input Validation, NULL Pointer Deref
Red Hat
busybox: incorrect handling of a special element in ash applet leads to denial of service when processing a crafted shell command
vendor_redhat·2021-11-09·CVSS 5.5
CVE-2021-42375 [MEDIUM] CWE-20 busybox: incorrect handling of a special element in ash applet leads to denial of service when processing a crafted shell command
busybox: incorrect handling of a special element in ash applet leads to denial of service when processing a crafted shell command
An incorrect handling of a special element in Busybox's ash applet leads to denial of service when processing a crafted shell command, due to the shell mistaking specific characters for reserved characters. This may be used for DoS under rare conditions of filtered command input.
A flaw was found in BusyBox, where it did not properly sanitize while processing a special element in ash, leading to a denial of service. The highest threat from this vulnerability is to system availability.
Package: busybox (Red Hat Enterprise Linux 6) - Not affected
Debian
CVE-2021-42375: busybox - An incorrect handling of a special element in Busybox's ash applet leads to deni...
vendor_debian·2021·CVSS 5.5
CVE-2021-42375 [MEDIUM] CVE-2021-42375: busybox - An incorrect handling of a special element in Busybox's ash applet leads to deni...
An incorrect handling of a special element in Busybox's ash applet leads to denial of service when processing a crafted shell command, due to the shell mistaking specific characters for reserved characters. This may be used for DoS under rare conditions of filtered command input.
Scope: local
bookworm: resolved (fixed in 1:1.35.0-1)
bullseye: open
forky: resolved (fixed in 1:1.35.0-1)
sid: resolved (fixed in 1:1.35.0-1)
trixie: resolved (fixed in 1:1.35.0-1)
GHSA
GHSA-h7xx-2pfg-qqhm: An incorrect handling of a special element in Busybox's ash applet leads to denial of service when processing a crafted shell command, due to the shel
ghsa_unreviewed·2022-05-24
CVE-2021-42375 [HIGH] CWE-159 GHSA-h7xx-2pfg-qqhm: An incorrect handling of a special element in Busybox's ash applet leads to denial of service when processing a crafted shell command, due to the shel
An incorrect handling of a special element in Busybox's ash applet leads to denial of service when processing a crafted shell command, due to the shell mistaking specific characters for reserved characters. This may be used for DoS under rare conditions of filtered command input.
OSV
CVE-2021-42375: An incorrect handling of a special element in Busybox's ash applet leads to denial of service when processing a crafted shell command, due to the shel
osv·2021-11-15·CVSS 5.5
CVE-2021-42375 [MEDIUM] CVE-2021-42375: An incorrect handling of a special element in Busybox's ash applet leads to denial of service when processing a crafted shell command, due to the shel
An incorrect handling of a special element in Busybox's ash applet leads to denial of service when processing a crafted shell command, due to the shell mistaking specific characters for reserved characters. This may be used for DoS under rare conditions of filtered command input.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://claroty.com/team82/research/unboxing-busybox-14-vulnerabilities-uncovered-by-claroty-jfroghttps://jfrog.com/blog/unboxing-busybox-14-new-vulnerabilities-uncovered-by-claroty-and-jfrog/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6T2TURBYYJGBMQTTN2DSOAIQGP7WCPGV/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UQXGOGWBIYWOIVXJVRKHZR34UMEHQBXS/https://security.netapp.com/advisory/ntap-20211223-0002/https://claroty.com/team82/research/unboxing-busybox-14-vulnerabilities-uncovered-by-claroty-jfroghttps://jfrog.com/blog/unboxing-busybox-14-new-vulnerabilities-uncovered-by-claroty-and-jfrog/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6T2TURBYYJGBMQTTN2DSOAIQGP7WCPGV/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UQXGOGWBIYWOIVXJVRKHZR34UMEHQBXS/https://security.netapp.com/advisory/ntap-20211223-0002/
2021-11-15
Published