ZeroHour

CVE-2021-42377

CVSS 3.1
9.8 critical
EPSS
4%p89
Published
()
Modified
Description

An attacker-controlled pointer free in Busybox's hush applet leads to denial of service and possible code execution when processing a crafted shell command, due to the shell mishandling the &&& string. This may be used for remote code execution under rare conditions of filtered command input.

Vendors
busyboxfedoraprojectnetapp
Products
busybox, fedora, cloud backup, hci management node, solidfire, h300s firmware, h500s firmware, h700s firmware, h300e firmware, h500e firmware, h700e firmware, h410s firmware
Weakness
CWE-590, CWE-763
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news