5.3
CVSSv3

CVE-2021-42374

Published: 15/11/2021 Updated: 07/11/2023
CVSS v2 Base Score: 3.3 | Impact Score: 4.9 | Exploitability Score: 3.4
CVSS v3 Base Score: 5.3 | Impact Score: 4.2 | Exploitability Score: 1
VMScore: 294
Vector: AV:L/AC:M/Au:N/C:P/I:N/A:P

Vulnerability Summary

An out-of-bounds heap read in Busybox's unlzma applet leads to information leak and denial of service when crafted LZMA-compressed input is decompressed. This can be triggered by any applet/format that

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

busybox busybox

fedoraproject fedora 33

fedoraproject fedora 34

netapp cloud backup -

netapp solidfire -

netapp hci management node -

netapp h300s_firmware -

netapp h500s_firmware -

netapp h700s_firmware -

netapp h300e_firmware -

netapp h500e_firmware -

netapp h700e_firmware -

netapp h410s_firmware -

Vendor Advisories

An out-of-bounds heap read in Busybox's unlzma applet leads to information leak and denial of service when crafted LZMA-compressed input is decompressed This can be triggered by any applet/format that ...
An out-of-bounds heap read in Busybox's unlzma applet before version 1340 leads to information leak and denial of service when crafted LZMA-compressed input is decompressed This can be triggered by any applet/format that internally supports LZMA compression ...