5.5
CVSSv3

CVE-2023-42363

Published: 27/11/2023 Updated: 30/11/2023
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 0

Vulnerability Summary

A use-after-free vulnerability exists in xasprintf function in xfuncs_printf.c:344 in BusyBox v.1.36.1.

Vulnerable Product Search on Vulmon Subscribe to Product

busybox busybox 1.36.1

Vendor Advisories

Debian Bug report logs - #1059050 busybox: CVE-2023-42363 Package: src:busybox; Maintainer for src:busybox is Debian Install System Team <debian-boot@listsdebianorg>; Reported by: Moritz Mühlenhoff <jmm@inutilorg> Date: Tue, 19 Dec 2023 21:21:03 UTC Severity: important Tags: security, upstream Forwarded to ht ...
DescriptionThe MITRE CVE dictionary describes this issue as: A use-after-free vulnerability was discovered in xasprintf function in xfuncs_printfc:344 in BusyBox v1361 ...