SUSE update for busybox



Published: 2023-09-27
Risk Medium
Patch available YES
Number of vulnerabilities 1
CVE-ID CVE-2022-48174
CWE-ID CWE-787
Exploitation vector Network
Public exploit N/A
Vulnerable software
Subscribe
Basesystem Module
Operating systems & Components / Operating system

SUSE Linux Enterprise Server for SAP Applications 15
Operating systems & Components / Operating system

SUSE Linux Enterprise Server 15
Operating systems & Components / Operating system

SUSE Linux Enterprise Real Time 15
Operating systems & Components / Operating system

SUSE Linux Enterprise High Performance Computing 15
Operating systems & Components / Operating system

SUSE Linux Enterprise Desktop 15
Operating systems & Components / Operating system

openSUSE Leap
Operating systems & Components / Operating system

busybox-warewulf3
Operating systems & Components / Operating system package or component

busybox-testsuite
Operating systems & Components / Operating system package or component

busybox-static
Operating systems & Components / Operating system package or component

busybox
Operating systems & Components / Operating system package or component

busybox-syslogd
Operating systems & Components / Operating system package or component

busybox-man
Operating systems & Components / Operating system package or component

busybox-hostname
Operating systems & Components / Operating system package or component

busybox-telnet
Operating systems & Components / Operating system package or component

busybox-netcat
Operating systems & Components / Operating system package or component

busybox-sh
Operating systems & Components / Operating system package or component

busybox-sendmail
Operating systems & Components / Operating system package or component

busybox-findutils
Operating systems & Components / Operating system package or component

busybox-coreutils
Operating systems & Components / Operating system package or component

busybox-cpio
Operating systems & Components / Operating system package or component

busybox-ncurses-utils
Operating systems & Components / Operating system package or component

busybox-tar
Operating systems & Components / Operating system package or component

busybox-traceroute
Operating systems & Components / Operating system package or component

busybox-bc
Operating systems & Components / Operating system package or component

busybox-util-linux
Operating systems & Components / Operating system package or component

busybox-psmisc
Operating systems & Components / Operating system package or component

busybox-attr
Operating systems & Components / Operating system package or component

busybox-diffutils
Operating systems & Components / Operating system package or component

busybox-bzip2
Operating systems & Components / Operating system package or component

busybox-which
Operating systems & Components / Operating system package or component

busybox-iputils
Operating systems & Components / Operating system package or component

busybox-wget
Operating systems & Components / Operating system package or component

busybox-policycoreutils
Operating systems & Components / Operating system package or component

busybox-grep
Operating systems & Components / Operating system package or component

busybox-xz
Operating systems & Components / Operating system package or component

busybox-selinux-tools
Operating systems & Components / Operating system package or component

busybox-dos2unix
Operating systems & Components / Operating system package or component

busybox-gzip
Operating systems & Components / Operating system package or component

busybox-vlan
Operating systems & Components / Operating system package or component

busybox-vi
Operating systems & Components / Operating system package or component

busybox-sed
Operating systems & Components / Operating system package or component

busybox-ed
Operating systems & Components / Operating system package or component

busybox-unzip
Operating systems & Components / Operating system package or component

busybox-tftp
Operating systems & Components / Operating system package or component

busybox-tunctl
Operating systems & Components / Operating system package or component

busybox-time
Operating systems & Components / Operating system package or component

busybox-net-tools
Operating systems & Components / Operating system package or component

busybox-adduser
Operating systems & Components / Operating system package or component

busybox-procps
Operating systems & Components / Operating system package or component

busybox-less
Operating systems & Components / Operating system package or component

busybox-kbd
Operating systems & Components / Operating system package or component

busybox-gawk
Operating systems & Components / Operating system package or component

busybox-patch
Operating systems & Components / Operating system package or component

busybox-sharutils
Operating systems & Components / Operating system package or component

busybox-whois
Operating systems & Components / Operating system package or component

busybox-links
Operating systems & Components / Operating system package or component

busybox-sysvinit-tools
Operating systems & Components / Operating system package or component

busybox-misc
Operating systems & Components / Operating system package or component

busybox-iproute2
Operating systems & Components / Operating system package or component

busybox-bind-utils
Operating systems & Components / Operating system package or component

busybox-kmod
Operating systems & Components / Operating system package or component

Vendor SUSE

Security Bulletin

This security bulletin contains one medium risk vulnerability.

1) Out-of-bounds write

EUVDB-ID: #VU80391

Risk: Medium

CVSSv3.1: 6.5 [CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2022-48174

CWE-ID: CWE-787 - Out-of-bounds write

Exploit availability: No

Description

The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a boundary error when processing untrusted input ash.c. A remote attacker can send specially crafted data to the application, trigger an out-of-bounds write and execute arbitrary code on the target system.

Mitigation

Update the affected package busybox to the latest version.

Vulnerable software versions

Basesystem Module: 15-SP5

SUSE Linux Enterprise Server for SAP Applications 15: SP5

SUSE Linux Enterprise Server 15: SP5

SUSE Linux Enterprise Real Time 15: SP5

SUSE Linux Enterprise High Performance Computing 15: SP5

SUSE Linux Enterprise Desktop 15: SP5

openSUSE Leap: 15.5

busybox-warewulf3: before 1.35.0-150500.10.3.3

busybox-testsuite: before 1.35.0-150500.10.3.3

busybox-static: before 1.35.0-150500.10.3.3

busybox: before 1.35.0-150500.10.3.3

busybox-syslogd: before 1.35.0-150500.7.2.3

busybox-man: before 1.35.0-150500.7.2.3

busybox-hostname: before 1.35.0-150500.7.2.3

busybox-telnet: before 1.35.0-150500.7.2.3

busybox-netcat: before 1.35.0-150500.7.2.3

busybox-sh: before 1.35.0-150500.7.2.3

busybox-sendmail: before 1.35.0-150500.7.2.3

busybox-findutils: before 1.35.0-150500.7.2.3

busybox-coreutils: before 1.35.0-150500.7.2.3

busybox-cpio: before 1.35.0-150500.7.2.3

busybox-ncurses-utils: before 1.35.0-150500.7.2.3

busybox-tar: before 1.35.0-150500.7.2.3

busybox-traceroute: before 1.35.0-150500.7.2.3

busybox-bc: before 1.35.0-150500.7.2.3

busybox-util-linux: before 1.35.0-150500.7.2.3

busybox-psmisc: before 1.35.0-150500.7.2.3

busybox-attr: before 1.35.0-150500.7.2.3

busybox-diffutils: before 1.35.0-150500.7.2.3

busybox-bzip2: before 1.35.0-150500.7.2.3

busybox-which: before 1.35.0-150500.7.2.3

busybox-iputils: before 1.35.0-150500.7.2.3

busybox-wget: before 1.35.0-150500.7.2.3

busybox-policycoreutils: before 1.35.0-150500.7.2.3

busybox-grep: before 1.35.0-150500.7.2.3

busybox-xz: before 1.35.0-150500.7.2.3

busybox-selinux-tools: before 1.35.0-150500.7.2.3

busybox-dos2unix: before 1.35.0-150500.7.2.3

busybox-gzip: before 1.35.0-150500.7.2.3

busybox-vlan: before 1.35.0-150500.7.2.3

busybox-vi: before 1.35.0-150500.7.2.3

busybox-sed: before 1.35.0-150500.7.2.3

busybox-ed: before 1.35.0-150500.7.2.3

busybox-unzip: before 1.35.0-150500.7.2.3

busybox-tftp: before 1.35.0-150500.7.2.3

busybox-tunctl: before 1.35.0-150500.7.2.3

busybox-time: before 1.35.0-150500.7.2.3

busybox-net-tools: before 1.35.0-150500.7.2.3

busybox-adduser: before 1.35.0-150500.7.2.3

busybox-procps: before 1.35.0-150500.7.2.3

busybox-less: before 1.35.0-150500.7.2.3

busybox-kbd: before 1.35.0-150500.7.2.3

busybox-gawk: before 1.35.0-150500.7.2.3

busybox-patch: before 1.35.0-150500.7.2.3

busybox-sharutils: before 1.35.0-150500.7.2.3

busybox-whois: before 1.35.0-150500.7.2.3

busybox-links: before 1.35.0-150500.7.2.3

busybox-sysvinit-tools: before 1.35.0-150500.7.2.3

busybox-misc: before 1.35.0-150500.7.2.3

busybox-iproute2: before 1.35.0-150500.7.2.3

busybox-bind-utils: before 1.35.0-150500.7.2.3

busybox-kmod: before 1.35.0-150500.7.2.3

External links

http://www.suse.com/support/update/announcement/2023/suse-su-20233820-1/


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###