{"id":"SUSE-SU-2022:3959-1","summary":"Security update for busybox","details":"This update for busybox fixes the following issues:\n\n- Enable switch_root\n  With this change virtme --force-initramfs works as expected.\n- Enable udhcpc\n\nbusybox was updated to 1.35.0\n\n- Adjust busybox.config for new features in find, date and cpio \n\n- Annotate CVEs already fixed in upstream, but not mentioned in .changes yet:\n\n* CVE-2017-16544 (bsc#1069412): Insufficient sanitization of filenames when autocompleting\n* CVE-2015-9261 (bsc#1102912): huft_build misuses a pointer, causing segfaults\n* CVE-2016-2147 (bsc#970663): out of bounds write (heap) due to integer underflow in udhcpc\n* CVE-2016-2148 (bsc#970662): heap-based buffer overflow in OPTION_6RD parsing\n* CVE-2016-6301 (bsc#991940): NTP server denial of service flaw\n* CVE-2017-15873 (bsc#1064976): The get_next_block function in archival/libarchive/decompress_bunzip2.c has an Integer Overflow\n* CVE-2017-15874 (bsc#1064978): archival/libarchive/decompress_unlzma.c has an Integer Underflow\n* CVE-2019-5747 (bsc#1121428): out of bounds read in udhcp components\n* CVE-2021-42373, CVE-2021-42374, CVE-2021-42375, CVE-2021-42376,\n  CVE-2021-42377, CVE-2021-42378, CVE-2021-42379, CVE-2021-42380,\n  CVE-2021-42381, CVE-2021-42382, CVE-2021-42383, CVE-2021-42384,\n  CVE-2021-42385, CVE-2021-42386 (bsc#1192869) : v1.34.0 bugfixes\n* CVE-2021-28831 (bsc#1184522): invalid free or segmentation fault via malformed gzip data\n* CVE-2018-20679 (bsc#1121426): out of bounds read in udhcp\n* CVE-2018-1000517 (bsc#1099260):  Heap-based buffer overflow in the retrieve_file_data()\n* CVE-2011-5325 (bsc#951562): tar directory traversal\n* CVE-2018-1000500 (bsc#1099263):  wget: Missing SSL certificate validation\n","modified":"2026-03-11T07:21:29.758421Z","published":"2022-11-11T14:38:22Z","related":["CVE-2011-5325","CVE-2015-9261","CVE-2016-2147","CVE-2016-2148","CVE-2016-6301","CVE-2017-15873","CVE-2017-15874","CVE-2017-16544","CVE-2018-1000500","CVE-2018-1000517","CVE-2018-20679","CVE-2019-5747","CVE-2021-28831","CVE-2021-42373","CVE-2021-42374","CVE-2021-42375","CVE-2021-42376","CVE-2021-42377","CVE-2021-42378","CVE-2021-42379","CVE-2021-42380","CVE-2021-42381","CVE-2021-42382","CVE-2021-42383","CVE-2021-42384","CVE-2021-42385","CVE-2021-42386"],"upstream":["CVE-2011-5325","CVE-2015-9261","CVE-2016-2147","CVE-2016-2148","CVE-2016-6301","CVE-2017-15873","CVE-2017-15874","CVE-2017-16544","CVE-2018-1000500","CVE-2018-1000517","CVE-2018-20679","CVE-2019-5747","CVE-2021-28831","CVE-2021-42373","CVE-2021-42374","CVE-2021-42375","CVE-2021-42376","CVE-2021-42377","CVE-2021-42378","CVE-2021-42379","CVE-2021-42380","CVE-2021-42381","CVE-2021-42382","CVE-2021-42383","CVE-2021-42384","CVE-2021-42385","CVE-2021-42386"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2022/suse-su-20223959-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1064976"},{"type":"REPORT","url":"https://bugzilla.suse.com/1064978"},{"type":"REPORT","url":"https://bugzilla.suse.com/1069412"},{"type":"REPORT","url":"https://bugzilla.suse.com/1099260"},{"type":"REPORT","url":"https://bugzilla.suse.com/1099263"},{"type":"REPORT","url":"https://bugzilla.suse.com/1102912"},{"type":"REPORT","url":"https://bugzilla.suse.com/1121426"},{"type":"REPORT","url":"https://bugzilla.suse.com/1121428"},{"type":"REPORT","url":"https://bugzilla.suse.com/1184522"},{"type":"REPORT","url":"https://bugzilla.suse.com/1192869"},{"type":"REPORT","url":"https://bugzilla.suse.com/951562"},{"type":"REPORT","url":"https://bugzilla.suse.com/970662"},{"type":"REPORT","url":"https://bugzilla.suse.com/970663"},{"type":"REPORT","url":"https://bugzilla.suse.com/991940"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2011-5325"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2015-9261"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-2147"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-2148"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-6301"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-15873"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-15874"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-16544"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-1000500"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-1000517"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-20679"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-5747"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-28831"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-42373"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-42374"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-42375"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-42376"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-42377"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-42378"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-42379"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-42380"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-42381"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-42382"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-42383"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-42384"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-42385"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-42386"}],"affected":[{"package":{"name":"busybox","ecosystem":"SUSE:Linux Enterprise Module for Basesystem 15 SP4","purl":"pkg:rpm/suse/busybox&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.35.0-150400.3.3.1"}]}],"ecosystem_specific":{"binaries":[{"busybox-static":"1.35.0-150400.3.3.1","busybox":"1.35.0-150400.3.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:3959-1.json"}},{"package":{"name":"busybox","ecosystem":"openSUSE:Leap 15.4","purl":"pkg:rpm/opensuse/busybox&distro=openSUSE%20Leap%2015.4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.35.0-150400.3.3.1"}]}],"ecosystem_specific":{"binaries":[{"busybox-testsuite":"1.35.0-150400.3.3.1","busybox-warewulf3":"1.35.0-150400.3.3.1","busybox":"1.35.0-150400.3.3.1","busybox-static":"1.35.0-150400.3.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:3959-1.json"}}],"schema_version":"1.7.5"}