Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
BusyBox DHCPv6 Client Heap Buffer Overflow via DNS_SERVERS
Vulnerability Description
BusyBox before commit 42202bf contains a heap buffer overflow vulnerability in the DHCPv6 client (udhcpc6) DNS_SERVERS option handler in networking/udhcp/d6_dhcpc.c that allows network-adjacent attackers to trigger memory corruption by sending a crafted DHCPv6 response with a malformed D6_OPT_DNS_SERVERS option. Attackers can exploit incorrect heap buffer allocation calculations in the option_to_env() function to cause denial of service or achieve arbitrary code execution on embedded systems without heap hardening.
CVSS Information
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Vulnerability Type
堆缓冲区溢出
Vulnerability Title
BusyBox 安全漏洞
Vulnerability Description
BusyBox是乌克兰Denis Vlasenko个人开发者的一套包含了多个linux命令和工具的应用程序。 BusyBox存在安全漏洞,该漏洞源于DHCPv6客户端udhcpc6的DNS_SERVERS选项处理程序中存在堆缓冲区溢出,允许网络相邻攻击者通过发送特制的DHCPv6响应触发内存损坏,攻击者可以利用option_to_env()函数中不正确的堆缓冲区分配计算导致拒绝服务或在没有堆加固的嵌入式系统上实现任意代码执行。
CVSS Information
N/A
Vulnerability Type
N/A