CVE-2021-28831
19.03.2021, 05:15
decompress_gunzip.c in BusyBox through 1.32.1 mishandles the error bit on the huft_build result pointer, with a resultant invalid free or segmentation fault, via malformed gzip data.Enginsight
| Vendor | Product | Version |
|---|---|---|
| busybox | busybox | 1.32.0 ≤ 𝑥 ≤ 1.32.1 |
| debian | debian_linux | 9.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| busybox |
|
Common Weakness Enumeration
References