Vulnerability Description
An incorrect handling of a special element in Busybox's ash applet leads to denial of service when processing a crafted shell command, due to the shell mistaking specific characters for reserved characters. This may be used for DoS under rare conditions of filtered command input.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Busybox | Busybox | 1.33.1 |
| Fedoraproject | Fedora | 33 |
| Netapp | Cloud Backup | - |
| Netapp | Hci Management Node | - |
| Netapp | Solidfire | - |
| Netapp | H300S Firmware | - |
| Netapp | H300S | - |
| Netapp | H500S Firmware | - |
| Netapp | H500S | - |
| Netapp | H700S Firmware | - |
| Netapp | H700S | - |
| Netapp | H300E Firmware | - |
| Netapp | H300E | - |
| Netapp | H500E Firmware | - |
| Netapp | H500E | - |
| Netapp | H700E Firmware | - |
| Netapp | H700E | - |
| Netapp | H410S Firmware | - |
| Netapp | H410S | - |
Related Weaknesses (CWE)
References
- https://claroty.com/team82/research/unboxing-busybox-14-vulnerabilities-uncovere
- https://jfrog.com/blog/unboxing-busybox-14-new-vulnerabilities-uncovered-by-clarThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://security.netapp.com/advisory/ntap-20211223-0002/Third Party Advisory
- https://claroty.com/team82/research/unboxing-busybox-14-vulnerabilities-uncovere
- https://jfrog.com/blog/unboxing-busybox-14-new-vulnerabilities-uncovered-by-clarThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://security.netapp.com/advisory/ntap-20211223-0002/Third Party Advisory
FAQ
What is CVE-2021-42375?
CVE-2021-42375 is a vulnerability with a CVSS score of 5.5 (MEDIUM). An incorrect handling of a special element in Busybox's ash applet leads to denial of service when processing a crafted shell command, due to the shell mistaking specific characters for reserved chara...
How severe is CVE-2021-42375?
CVE-2021-42375 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-42375?
Check the references section above for vendor advisories and patch information. Affected products include: Busybox Busybox, Fedoraproject Fedora, Netapp Cloud Backup, Netapp Hci Management Node, Netapp Solidfire.