[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

251139

 
 

909

 
 

196159

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

SUSE-SU-2022:3959-1 -- SLES busybox

ID: oval:org.secpod.oval:def:89047876Date: (C)2022-11-21   (M)2023-12-20
Class: PATCHFamily: unix




This update for busybox fixes the following issues: - Enable switch_root With this change virtme --force-initramfs works as expected. - Enable udhcpc busybox was updated to 1.35.0 - Adjust busybox.config for new features in find, date and cpio - Annotate CVEs already fixed in upstream, but not mentioned in .changes yet: * CVE-2017-16544 : Insufficient sanitization of filenames when autocompleting * CVE-2015-9261 : huft_build misuses a pointer, causing segfaults * CVE-2016-2147 : out of bounds write due to integer underflow in udhcpc * CVE-2016-2148 : heap-based buffer overflow in OPTION_6RD parsing * CVE-2016-6301 : NTP server denial of service flaw * CVE-2017-15873 : The get_next_block function in archival/libarchive/decompress_bunzip2.c has an Integer Overflow * CVE-2017-15874 : archival/libarchive/decompress_unlzma.c has an Integer Underflow * CVE-2019-5747 : out of bounds read in udhcp components * CVE-2021-42373, CVE-2021-42374, CVE-2021-42375, CVE-2021-42376, CVE-2021-42377, CVE-2021-42378, CVE-2021-42379, CVE-2021-42380, CVE-2021-42381, CVE-2021-42382, CVE-2021-42383, CVE-2021-42384, CVE-2021-42385, CVE-2021-42386 : v1.34.0 bugfixes * CVE-2021-28831 : invalid free or segmentation fault via malformed gzip data * CVE-2018-20679 : out of bounds read in udhcp * CVE-2018-1000517 : Heap-based buffer overflow in the retrieve_file_data * CVE-2011-5325 : tar directory traversal * CVE-2018-1000500 : wget: Missing SSL certificate validation

Platform:
SUSE Linux Enterprise Desktop 15 SP4
SUSE Linux Enterprise Server 15 SP4
Product:
busybox
Reference:
SUSE-SU-2022:3959-1
CVE-2011-5325
CVE-2015-9261
CVE-2016-2147
CVE-2016-2148
CVE-2016-6301
CVE-2017-15873
CVE-2017-15874
CVE-2017-16544
CVE-2018-1000500
CVE-2018-1000517
CVE-2018-20679
CVE-2019-5747
CVE-2021-28831
CVE-2021-42373
CVE-2021-42374
CVE-2021-42375
CVE-2021-42376
CVE-2021-42377
CVE-2021-42378
CVE-2021-42379
CVE-2021-42380
CVE-2021-42381
CVE-2021-42382
CVE-2021-42383
CVE-2021-42384
CVE-2021-42385
CVE-2021-42386
CVE    27
CVE-2011-5325
CVE-2016-2147
CVE-2016-2148
CVE-2016-6301
...

© SecPod Technologies