5.5
CVSSv3

CVE-2021-42373

Published: 15/11/2021 Updated: 07/11/2023
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

A NULL pointer dereference in Busybox's man applet leads to denial of service when a section name is supplied but no page argument is given

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

busybox busybox 1.33.1

busybox busybox 1.33.0

fedoraproject fedora 33

fedoraproject fedora 34

netapp cloud backup -

netapp solidfire -

netapp hci management node -

netapp h300s_firmware -

netapp h500s_firmware -

netapp h700s_firmware -

netapp h300e_firmware -

netapp h500e_firmware -

netapp h700e_firmware -

netapp h410s_firmware -

Vendor Advisories

Debian Bug report logs - #999567 busybox: CVE-2021-42373 through CVE-2021-42386 (fixed in 134) Package: busybox; Maintainer for busybox is Debian Install System Team <debian-boot@listsdebianorg>; Source for busybox is src:busybox (PTS, buildd, popcon) Reported by: Diederik de Haas <dididebian@cknoworg> Date: Fri ...
A NULL pointer dereference in Busybox's man applet leads to denial of service when a section name is supplied but no page argument is given ...
A NULL pointer dereference in Busybox's man applet before version 1340 leads to denial of service when a section name is supplied but no page argument is given ...