Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-42363
HistoryNov 27, 2023 - 12:00 a.m.

CVE-2023-42363

2023-11-2700:00:00
ubuntu.com
ubuntu.com
21
busybox
vulnerability
xasprintf
xfuncs_printf.c
use-after-free
2023
cve-2023-42363

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

AI Score

5.5

Confidence

High

EPSS

0

Percentile

12.7%

A use-after-free vulnerability was discovered in xasprintf function in
xfuncs_printf.c:344 in BusyBox v.1.36.1.

Bugs

Notes

Author Note
mdeslaur as of 2024-07-18, there is no fix from upstream for this issue, only a fix proposed on the mailing list
iconstantin proposed fix has been merged, bug not yet updated as of 2024-07-24

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

AI Score

5.5

Confidence

High

EPSS

0

Percentile

12.7%