SUSE-SU-2022:3959-1

Source
https://www.suse.com/support/update/announcement/2022/suse-su-20223959-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:3959-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2022:3959-1
Related
Published
2022-11-11T14:38:22Z
Modified
2022-11-11T14:38:22Z
Summary
Security update for busybox
Details

This update for busybox fixes the following issues:

  • Enable switch_root With this change virtme --force-initramfs works as expected.
  • Enable udhcpc

busybox was updated to 1.35.0

  • Adjust busybox.config for new features in find, date and cpio

  • Annotate CVEs already fixed in upstream, but not mentioned in .changes yet:

  • CVE-2017-16544 (bsc#1069412): Insufficient sanitization of filenames when autocompleting

  • CVE-2015-9261 (bsc#1102912): huft_build misuses a pointer, causing segfaults
  • CVE-2016-2147 (bsc#970663): out of bounds write (heap) due to integer underflow in udhcpc
  • CVE-2016-2148 (bsc#970662): heap-based buffer overflow in OPTION_6RD parsing
  • CVE-2016-6301 (bsc#991940): NTP server denial of service flaw
  • CVE-2017-15873 (bsc#1064976): The getnextblock function in archival/libarchive/decompress_bunzip2.c has an Integer Overflow
  • CVE-2017-15874 (bsc#1064978): archival/libarchive/decompress_unlzma.c has an Integer Underflow
  • CVE-2019-5747 (bsc#1121428): out of bounds read in udhcp components
  • CVE-2021-42373, CVE-2021-42374, CVE-2021-42375, CVE-2021-42376, CVE-2021-42377, CVE-2021-42378, CVE-2021-42379, CVE-2021-42380, CVE-2021-42381, CVE-2021-42382, CVE-2021-42383, CVE-2021-42384, CVE-2021-42385, CVE-2021-42386 (bsc#1192869) : v1.34.0 bugfixes
  • CVE-2021-28831 (bsc#1184522): invalid free or segmentation fault via malformed gzip data
  • CVE-2018-20679 (bsc#1121426): out of bounds read in udhcp
  • CVE-2018-1000517 (bsc#1099260): Heap-based buffer overflow in the retrievefiledata()
  • CVE-2011-5325 (bsc#951562): tar directory traversal
  • CVE-2018-1000500 (bsc#1099263): wget: Missing SSL certificate validation
References

Affected packages

SUSE:Linux Enterprise Module for Basesystem 15 SP4 / busybox

Package

Name
busybox
Purl
pkg:rpm/suse/busybox&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.35.0-150400.3.3.1

Ecosystem specific

{
    "binaries": [
        {
            "busybox": "1.35.0-150400.3.3.1",
            "busybox-static": "1.35.0-150400.3.3.1"
        }
    ]
}

openSUSE:Leap 15.4 / busybox

Package

Name
busybox
Purl
pkg:rpm/opensuse/busybox&distro=openSUSE%20Leap%2015.4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.35.0-150400.3.3.1

Ecosystem specific

{
    "binaries": [
        {
            "busybox": "1.35.0-150400.3.3.1",
            "busybox-testsuite": "1.35.0-150400.3.3.1",
            "busybox-static": "1.35.0-150400.3.3.1",
            "busybox-warewulf3": "1.35.0-150400.3.3.1"
        }
    ]
}