A NULL pointer dereference in Busybox's hush applet leads to denial of service when processing a crafted shell command, due to missing validation after a \x03 delimiter character. This may be used for DoS under very rare conditions of filtered command input.
2021-11-15T21:15:07.647
2024-11-21T06:27:41.533
Modified
CVSSv3.1: 5.5 (MEDIUM)
AV:L/AC:M/Au:N/C:N/I:N/A:P
3.4
2.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | busybox | busybox | < 1.34.0 | Yes |
| Operating System | fedoraproject | fedora | 33 | Yes |
| Operating System | fedoraproject | fedora | 34 | Yes |
| Application | netapp | cloud_backup | - | Yes |
| Application | netapp | hci_management_node | - | Yes |
| Application | netapp | solidfire | - | Yes |
| Operating System | netapp | h300s_firmware | - | Yes |
| Hardware | netapp | h300s | - | No |
| Operating System | netapp | h500s_firmware | - | Yes |
| Hardware | netapp | h500s | - | No |
| Operating System | netapp | h700s_firmware | - | Yes |
| Hardware | netapp | h700s | - | No |
| Operating System | netapp | h300e_firmware | - | Yes |
| Hardware | netapp | h300e | - | No |
| Operating System | netapp | h500e_firmware | - | Yes |
| Hardware | netapp | h500e | - | No |
| Operating System | netapp | h700e_firmware | - | Yes |
| Hardware | netapp | h700e | - | No |
| Operating System | netapp | h410s_firmware | - | Yes |
| Hardware | netapp | h410s | - | No |