Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:10798
HistoryJan 15, 2019 - 8:52 a.m.

Remote Code Execution (RCE)

2019-01-1508:52:23
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
13

0.103 Low

EPSS

Percentile

95.0%

busybox is vulnerable to remote code execution (RCE) attacks. The vulnerability exists in the decompress function in compress42.c in (1) ncompress 4.2.4 and (2) liblzw allows remote attackers to cause a denial of service (crash), and possibly execute arbitrary code, via crafted data that leads to a buffer underflow.

References