ALPINE-CVE-2018-20679 PUBLISHED CVSS 7.5 HIGH

An issue was discovered in BusyBox before 1.30.0. An out of bounds read in udhcp components (consumed by the DHCP server, client, and relay) allows a remote attacker to leak sensitive information from the stack by sending a crafted DHCP message. This is related to verification in udhcp_get_option() in networking/udhcp/common.c that 4-byte options are indeed 4 bytes.

Risk Scores

CVSS v3.0
7.5
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected Products

VendorProductVersions
Alpine:v3.23busybox1.29.3-r9, 0, 1.12.1-r1
Alpine:v3.15busybox1.29.3-r9, 0, 1.12.1-r1
Alpine:v3.11busybox1.12.1-r5, 0, 1.29.3-r9
Alpine:v3.13busybox1.29.3-r9, 1.29.3-r8, 1.29.3-r7
Alpine:v3.17busybox1.12.1-r1, 1.29.3-r9, 1.29.3-r8
Alpine:v3.9busybox1.12.1-r5, 1.12.1-r6, 1.13.0-r1
Alpine:v3.16busybox1.24.2-r2, 1.29.3-r9, 1.29.3-r8
Alpine:v3.21busybox1.29.3-r8, 1.29.3-r7, 1.29.3-r6
Alpine:v3.14busybox1.19.3-r1, 0, 1.12.1-r1
Alpine:v3.12busybox0, 1.12.1-r1, 1.12.1-r5
Alpine:v3.20busybox0, 1.29.3-r9, 1.29.3-r8
Alpine:v3.19busybox1.23.0-r3, 1.12.1-r5, 1.12.1-r6
Alpine:v3.22busybox0, 1.12.1-r1, 1.12.1-r5
Alpine:v3.10busybox1.19.3-r8, 1.29.3-r9, 1.29.3-r8
Alpine:v3.18busybox1.13.1-r0, 1.29.3-r9, 1.29.3-r8

Timeline

References

Open in Interactive Console →