1.9
CVSSv2

CVE-2021-42375

Published: 15/11/2021 Updated: 07/11/2023
CVSS v2 Base Score: 1.9 | Impact Score: 2.9 | Exploitability Score: 3.4
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 169
Vector: AV:L/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

An incorrect handling of a special element in Busybox's ash applet leads to denial of service when processing a crafted shell command, due to the shell mistaking specific characters for reserved characters. This may be used for DoS under rare conditions of filtered command input.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

busybox busybox 1.33.1

fedoraproject fedora 33

fedoraproject fedora 34

netapp cloud backup -

netapp solidfire -

netapp hci management node -

netapp h300s_firmware -

netapp h500s_firmware -

netapp h700s_firmware -

netapp h300e_firmware -

netapp h500e_firmware -

netapp h700e_firmware -

netapp h410s_firmware -

Vendor Advisories

An incorrect handling of a special element in Busybox's ash applet leads to denial of service when processing a crafted shell command, due to the shell mistaking specific characters for reserved characters This may be used for DoS under rare conditions of filtered command input ...
An incorrect handling of a special element in Busybox's ash applet before version 1340 leads to denial of service when processing a crafted shell command, due to the shell mistaking specific characters for reserved characters This may be used for denial service under rare conditions of filtered command input ...