There are 6 open security issues in bookworm.
6 issues left for the package maintainer to handle:
- CVE-2022-48174:
(postponed; to be fixed through a stable update)
There is a stack overflow vulnerability in ash.c:6030 in busybox before 1.35. In the environment of Internet of Vehicles, this vulnerability can be executed from command to arbitrary code execution.
- CVE-2023-39810:
(postponed; to be fixed through a stable update)
An issue in the CPIO command of Busybox v1.33.2 allows attackers to execute a directory traversal.
- CVE-2023-42363:
(needs triaging)
A use-after-free vulnerability was discovered in xasprintf function in xfuncs_printf.c:344 in BusyBox v.1.36.1.
- CVE-2023-42364:
(postponed; to be fixed through a stable update)
A use-after-free vulnerability in BusyBox v.1.36.1 allows attackers to cause a denial of service via a crafted awk pattern in the awk.c evaluate function.
- CVE-2023-42365:
(postponed; to be fixed through a stable update)
A use-after-free vulnerability was discovered in BusyBox v.1.36.1 via a crafted awk pattern in the awk.c copyvar function.
- CVE-2023-42366:
(postponed; to be fixed through a stable update)
A heap-buffer-overflow was discovered in BusyBox v.1.36.1 in the next_token function at awk.c:1159.
You can find information about how to handle these issues in the security team's documentation.