Input validation error in BusyBox - CVE-2014-9645

 

Input validation error in BusyBox - CVE-2014-9645

Published: March 12, 2017 / Updated: August 3, 2020


Vulnerability identifier: #VU33083
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2014-9645
CWE-ID: CWE-20
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local authenticated user to manipulate data.

The add_probe function in modutils/modprobe.c in BusyBox before 1.23.0 allows local users to bypass intended restrictions on loading kernel modules via a / (slash) character in a module name, as demonstrated by an "ifconfig /usbserial up" command or a "mount -t /snd_pcm none /" command.


Affected software

BusyBox
Gentoo Linux
SUSE CaaS Platform
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Enterprise Storage
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Desktop
openSUSE Leap
busybox (Alpine package)
busybox
busybox-static
busybox-testsuite
busybox-warewulf3
busybox-tar
busybox-patch
busybox-sysvinit-tools
busybox-syslogd
busybox-sharutils
busybox-sh
busybox-sendmail
busybox-selinux-tools
busybox-sed
busybox-psmisc
busybox-procps
busybox-policycoreutils
busybox-xz
busybox-telnet
busybox-tftp
busybox-time
busybox-traceroute
busybox-tunctl
busybox-unzip
busybox-util-linux
busybox-vi
busybox-vlan
busybox-wget
busybox-which
busybox-whois
busybox-grep
busybox-adduser
busybox-attr
busybox-bc
busybox-bind-utils
busybox-bzip2
busybox-coreutils
busybox-cpio
busybox-diffutils
busybox-dos2unix
busybox-ed
busybox-findutils
busybox-gawk
busybox-netcat
busybox-gzip
busybox-hostname
busybox-iproute2
busybox-iputils
busybox-kbd
busybox-kmod
busybox-less
busybox-links
busybox-man
busybox-misc
busybox-ncurses-utils
busybox-net-tools

How to mitigate CVE-2014-9645

Install update from vendor's website.

BusyBox - update to 1.23.0
busybox (Alpine package) - update to 1.22.1-r15
busybox - addressed in versions 1.35.0-4.3.1, 1.35.0-150000.4.14.1, 1.35.0-150400.3.8.1
busybox-static - addressed in versions 1.35.0-150000.4.14.1, 1.35.0-150400.3.8.1
busybox-testsuite - update to 1.35.0-150400.3.8.1
busybox-warewulf3 - update to 1.35.0-150400.3.8.1
busybox-tar - update to 1.35.0-150400.4.3.14
busybox-patch - update to 1.35.0-150400.4.3.14
busybox-sysvinit-tools - update to 1.35.0-150400.4.3.14
busybox-syslogd - update to 1.35.0-150400.4.3.14
busybox-sharutils - update to 1.35.0-150400.4.3.14
busybox-sh - update to 1.35.0-150400.4.3.14
busybox-sendmail - update to 1.35.0-150400.4.3.14
busybox-selinux-tools - update to 1.35.0-150400.4.3.14
busybox-sed - update to 1.35.0-150400.4.3.14
busybox-psmisc - update to 1.35.0-150400.4.3.14
busybox-procps - update to 1.35.0-150400.4.3.14
busybox-policycoreutils - update to 1.35.0-150400.4.3.14
busybox-xz - update to 1.35.0-150400.4.3.14
busybox-telnet - update to 1.35.0-150400.4.3.14
busybox-tftp - update to 1.35.0-150400.4.3.14
busybox-time - update to 1.35.0-150400.4.3.14
busybox-traceroute - update to 1.35.0-150400.4.3.14
busybox-tunctl - update to 1.35.0-150400.4.3.14
busybox-unzip - update to 1.35.0-150400.4.3.14
busybox-util-linux - update to 1.35.0-150400.4.3.14
busybox-vi - update to 1.35.0-150400.4.3.14
busybox-vlan - update to 1.35.0-150400.4.3.14
busybox-wget - update to 1.35.0-150400.4.3.14
busybox-which - update to 1.35.0-150400.4.3.14
busybox-whois - update to 1.35.0-150400.4.3.14
busybox-grep - update to 1.35.0-150400.4.3.14
busybox-adduser - update to 1.35.0-150400.4.3.14
busybox-attr - update to 1.35.0-150400.4.3.14
busybox-bc - update to 1.35.0-150400.4.3.14
busybox-bind-utils - update to 1.35.0-150400.4.3.14
busybox-bzip2 - update to 1.35.0-150400.4.3.14
busybox-coreutils - update to 1.35.0-150400.4.3.14
busybox-cpio - update to 1.35.0-150400.4.3.14
busybox-diffutils - update to 1.35.0-150400.4.3.14
busybox-dos2unix - update to 1.35.0-150400.4.3.14
busybox-ed - update to 1.35.0-150400.4.3.14
busybox-findutils - update to 1.35.0-150400.4.3.14
busybox-gawk - update to 1.35.0-150400.4.3.14
busybox-netcat - update to 1.35.0-150400.4.3.14
busybox-gzip - update to 1.35.0-150400.4.3.14
busybox-hostname - update to 1.35.0-150400.4.3.14
busybox-iproute2 - update to 1.35.0-150400.4.3.14
busybox-iputils - update to 1.35.0-150400.4.3.14
busybox-kbd - update to 1.35.0-150400.4.3.14
busybox-kmod - update to 1.35.0-150400.4.3.14
busybox-less - update to 1.35.0-150400.4.3.14
busybox-links - update to 1.35.0-150400.4.3.14
busybox-man - update to 1.35.0-150400.4.3.14
busybox-misc - update to 1.35.0-150400.4.3.14
busybox-ncurses-utils - update to 1.35.0-150400.4.3.14
busybox-net-tools - update to 1.35.0-150400.4.3.14

External References

Related Security Bulletins