CVE-2021-42378

Updated on 15 Nov 2021

Severity

7.2 High severity

Details

CVSS score
7.2
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Overview

About vulnerability

A use-after-free in Busybox’s awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the getvar_i function

Details

Affected packages:
busybox @ 1.22.0 (+2 more)
A use-after-free in Busybox’s awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the getvar_i function

Fixes