CVE-2021-42374
15.11.2021, 21:15
An out-of-bounds heap read in Busybox's unlzma applet leads to information leak and denial of service when crafted LZMA-compressed input is decompressed. This can be triggered by any applet/format thatEnginsight
| Vendor | Product | Version |
|---|---|---|
| busybox | busybox | 1.27.0 ≤ 𝑥 ≤ 1.33.1 |
| netapp | cloud_backup | - |
| netapp | hci_management_node | - |
| netapp | solidfire | - |
| netapp | h300s_firmware | - |
| netapp | h500s_firmware | - |
| netapp | h700s_firmware | - |
| netapp | h300e_firmware | - |
| netapp | h500e_firmware | - |
| netapp | h700e_firmware | - |
| netapp | h410s_firmware | - |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Common Weakness Enumeration
References