gpp_maybe
Security update for busybox
SUSE-SLE-Module-Basesystem-15-SP4-2022-3959
This update for busybox fixes the following issues: - Enable switch_root With this change virtme --force-initramfs works as expected. - Enable udhcpc busybox was updated to 1.35.0 - Adjust busybox.config for new features in find, date and cpio - Annotate CVEs already fixed in upstream, but not mentioned in .changes yet: * CVE-2017-16544 (bsc#1069412): Insufficient sanitization of filenames when autocompleting * CVE-2015-9261 (bsc#1102912): huft_build misuses a pointer, causing segfaults * CVE-2016-2147 (bsc#970663): out of bounds write (heap) due to integer underflow in udhcpc * CVE-2016-2148 (bsc#970662): heap-based buffer overflow in OPTION_6RD parsing * CVE-2016-6301 (bsc#991940): NTP server denial of service flaw * CVE-2017-15873 (bsc#1064976): The get_next_block function in archival/libarchive/decompress_bunzip2.c has an Integer Overflow * CVE-2017-15874 (bsc#1064978): archival/libarchive/decompress_unlzma.c has an Integer Underflow * CVE-2019-5747 (bsc#1121428): out of bounds read in udhcp components * CVE-2021-42373, CVE-2021-42374, CVE-2021-42375, CVE-2021-42376, CVE-2021-42377, CVE-2021-42378, CVE-2021-42379, CVE-2021-42380, CVE-2021-42381, CVE-2021-42382, CVE-2021-42383, CVE-2021-42384, CVE-2021-42385, CVE-2021-42386 (bsc#1192869) : v1.34.0 bugfixes * CVE-2021-28831 (bsc#1184522): invalid free or segmentation fault via malformed gzip data * CVE-2018-20679 (bsc#1121426): out of bounds read in udhcp * CVE-2018-1000517 (bsc#1099260): Heap-based buffer overflow in the retrieve_file_data() * CVE-2011-5325 (bsc#951562): tar directory traversal * CVE-2018-1000500 (bsc#1099263): wget: Missing SSL certificate validation
-
Release DateNov 11 2022
-
ReferencesBugzilla: 970662, 1121428, 1064978, 1184522, 1099263, 1099260, 1121426, 951562, 1064976, 970663, 1192869, 991940, 1102912, 1069412
CVEs: CVE-2021-42380, CVE-2017-15874, CVE-2021-42382, CVE-2021-42383, CVE-2021-42381, CVE-2021-42375, CVE-2021-42378, CVE-2021-42376, CVE-2016-2147, CVE-2016-2148, CVE-2021-42386, CVE-2017-15873, CVE-2021-28831, CVE-2015-9261, CVE-2019-5747, CVE-2021-42379, CVE-2021-42374, CVE-2021-42384, CVE-2017-16544, CVE-2016-6301, CVE-2021-42377, CVE-2011-5325, CVE-2021-42373, CVE-2021-42385, CVE-2018-20679, CVE-2018-1000500, CVE-2018-1000517 -
Typesecurity
-
Severityimportant
cloud_download Downloads
Basesystem Module 15.4 aarch64
-
Packagesbusybox
Minimalist variant of UNIX utilities linked in a single executablebusybox-static1.35.0-150400.3.3.1 lock rpm lock src
Static linked version of Busybox, a compact UNIX utility collection1.35.0-150400.3.3.1 lock rpm
Basesystem Module 15.4 ppc64le
-
Packagesbusybox
Minimalist variant of UNIX utilities linked in a single executablebusybox-static1.35.0-150400.3.3.1 lock rpm lock src
Static linked version of Busybox, a compact UNIX utility collection1.35.0-150400.3.3.1 lock rpm
Basesystem Module 15.4 s390x
-
Packagesbusybox
Minimalist variant of UNIX utilities linked in a single executablebusybox-static1.35.0-150400.3.3.1 lock rpm lock src
Static linked version of Busybox, a compact UNIX utility collection1.35.0-150400.3.3.1 lock rpm
Basesystem Module 15.4 x86_64
-
Packagesbusybox
Minimalist variant of UNIX utilities linked in a single executablebusybox-static1.35.0-150400.3.3.1 lock rpm lock src
Static linked version of Busybox, a compact UNIX utility collection1.35.0-150400.3.3.1 lock rpm