archival/libarchive/decompress_unlzma.c in BusyBox 1.27.2 has an Integer Underflow that leads to a read access violation.
CVSS Details
- CVSS 3.1 Base Score: 5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N)
- CVSS 3.0 Base Score: 5.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade busybox | Nov 24, 2017 | Oct 24, 2017 |
| Debian | — | Upgrade busybox | Jul 30, 2024 | Oct 24, 2017 |
| Gentoo Linux | — | Upgrade sys-apps/busybox. | Mar 27, 2018 | Oct 24, 2017 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Oct 22, 2017 |
| Suse | — | Upgrade busybox-staticUpgrade busybox | Jan 21, 2022 | Oct 24, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub