A use-after-free in Busybox 1.35-x's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the copyvar function.
2022-05-18T15:15:10.240
2024-11-21T07:02:09.397
Modified
CVSSv3.1: 7.8 (HIGH)
AV:N/AC:M/Au:N/C:P/I:P/A:P
8.6
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | busybox | busybox | 1.35.0 | Yes |
Operating System | siemens | scalance_sc622-2c_firmware | < 3.0 | Yes |
Hardware | siemens | scalance_sc622-2c | - | No |
Operating System | siemens | scalance_sc626-2c_firmware | < 3.0 | Yes |
Hardware | siemens | scalance_sc626-2c | - | No |
Operating System | siemens | scalance_sc632-2c_firmware | < 3.0 | Yes |
Hardware | siemens | scalance_sc632-2c | - | No |
Operating System | siemens | scalance_sc636-2c_firmware | < 3.0 | Yes |
Hardware | siemens | scalance_sc636-2c | - | No |
Operating System | siemens | scalance_sc642-2c_firmware | < 3.0 | Yes |
Hardware | siemens | scalance_sc642-2c | - | No |
Operating System | siemens | scalance_sc646-2c_firmware | < 3.0 | Yes |
Hardware | siemens | scalance_sc646-2c | - | No |