摘要:
An attacker-controlled pointer free in Busybox s hush applet leads to denial of service and possible code execution when processing a crafted shell command, due to the shell mishandling the &&& string. This may be used for remote code execution under rare conditions of filtered command input.
安全等级: Low
公告ID: KylinSec-SA-2022-2788
发布日期: 2022年7月22日
关联CVE: CVE-2021-42377
An attacker-controlled pointer free in Busybox s hush applet leads to denial of service and possible code execution when processing a crafted shell command, due to the shell mishandling the &&& string. This may be used for remote code execution under rare conditions of filtered command input.
cve名称 | 产品 | 组件 | 是否受影响 |
---|---|---|---|
CVE-2021-42377 | KY3.4-4A | busybox | Unaffected |
CVE-2021-42377 | KY3.4-5 | busybox | Unaffected |
CVE-2021-42377 | KY3.5.1 | busybox | Unaffected |