#VU16958 Out-of-bounds read in BusyBox - CVE-2018-20679
Published: January 14, 2019 / Updated: June 4, 2019
BusyBox
busybox.net
Description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to a boundary condition in udhcp components (consumed by the DHCP server, client, and relay). A remote attacker can leak sensitive information from the stack by sending a crafted DHCP message.