[3.3] busybox: Multiple vulnerabilities (CVE-2017-15873, CVE-2017-16544)
CVE-2017-15873: Integer overflow in the get_next_block function
The get_next_block function in
archival/libarchive/decompress_bunzip2.c in BusyBox 1.27.2
has an Integer Overflow that may lead to a write access violation.
CVE-2017-16544: Insufficient sanitization of filenames when autocompleting
In the add_match function in libbb/lineedit.c in BusyBox through
1.27.2, the tab autocomplete feature of the shell,
used to get a list of filenames in a directory, does not sanitize filenames and results in executing any escape
sequence in the terminal. This could potentially result in code execution, arbitrary file writes, or other attacks.
(from redmine: issue id 8191, created on 2017-11-22, closed on 2017-11-23)
- parent #8186 (closed)
- Revision 9c61af0b by Natanael Copa on 2017-11-23T08:54:33Z:
main/busybox: secfixes for CVE-2017-15873,CVE-2017-16544 fixes #8191