Busybox CVE-2022-30065 and CVE-2022-28391
Package Information
- Package name: busybox
- Package version: 1.35.0-r17
- Alpine version:
3.16.9
NAME="Alpine Linux"
ID=alpine
VERSION_ID=3.16.9
PRETTY_NAME="Alpine Linux v3.16"
HOME_URL="https://alpinelinux.org/"
BUG_REPORT_URL="https://gitlab.alpinelinux.org/alpine/aports/-/issues"
- Alpine architecture: x86_64
Summary
CVE-2022-30065 A use-after-free in Busybox 1.35-x's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the copyvar function
CVE-2022-28391 BusyBox through 1.35.0 allows remote attackers to execute arbitrary code if netstat is used to print a DNS PTR record's value to a VT compatible terminal. Alternatively, the attacker could choose to change the terminal's colors.