| Summary: | busybox new security issue CVE-2022-30065 | ||
|---|---|---|---|
| Product: | Mageia | Reporter: | David Walser <luigiwalser> |
| Component: | Security | Assignee: | QA Team <qa-bugs> |
| Status: | RESOLVED FIXED | QA Contact: | Sec team <security> |
| Severity: | normal | ||
| Priority: | Normal | CC: | andrewsfarm, brtians1, davidwhodgins, sysadmin-bugs |
| Version: | 8 | Keywords: | advisory, validated_update |
| Target Milestone: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | MGA8-64-OK | ||
| Source RPM: | busybox-1.35.0-3.mga9.src.rpm | CVE: | |
| Status comment: | |||
|
Description
David Walser
2022-12-02 17:33:26 CET
David Walser
2022-12-02 17:33:44 CET
Whiteboard:
(none) =>
MGA8TOO Assigning to you, Stig as you seem to have been most involved with busybox recently. Assignee:
bugsquad =>
smelror Pushed fix to Cauldron. Whiteboard:
MGA8TOO =>
(none) Advisory ======== This update fixes CVE-2022-30065. A use-after-free in Busybox 1.35-x's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the copyvar function. References ========== http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30065 Files ===== Uploaded to core/updates_testing busybox-1.34.1-1.2.mga8 busybox-static-1.34.1-1.2.mga8 from busybox-1.34.1-1.2.mga8.src.rpm Assignee:
smelror =>
qa-bugs
David Walser
2022-12-02 21:49:42 CET
Status comment:
Patch available from upstream =>
(none) Installed above
usual commands working. I'm a bit awkward in awk, but hey.
$ busybox sh
~ $ awk '{ print $1, $2, $3 , $4, $5, $6, $7, $8, $9 }' pg69503.txt
command worked and didn't crash
~/awktest $ awk '{sub(/Th/,"F")}1' *
last few lines in text
Fis website includes information about Project Gutenberg-tm,
including how to make donations to the Project Gutenberg Literary
Archive Foundation, how to help produce our new eBooks, and how to
subscribe to our email newsletter to hear about new eBooks.
more fun
~/awktest $ awk '{sub(/t/,"f")}1' *
This websife includes information about Project Gutenberg-tm,
including how fo make donations to the Project Gutenberg Literary
Archive Foundafion, how to help produce our new eBooks, and how to
subscribe fo our email newsletter to hear about new eBooks.
seems awk is working in busybox as are other commands. I didn't test all 400 of them.CC:
(none) =>
brtians1 $ uname -a Linux localhost.localdomain 5.15.79-desktop-1.mga8 #1 SMP Wed Nov 16 16:07:06 UTC 2022 x86_64 x86_64 x86_64 GNU/Linux Whiteboard:
(none) =>
MGA8-64-OK Validating. Advisory in comment 3. Keywords:
(none) =>
validated_update
Dave Hodgins
2022-12-13 02:29:46 CET
Keywords:
(none) =>
advisory An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGASA-2022-0458.html Resolution:
(none) =>
FIXED |