{"id":"SUSE-SU-2022:4253-1","summary":"Security update for busybox","details":"This update for busybox fixes the following issues:\n\n- CVE-2014-9645: Fixed loading of unwanted modules with / (bsc#914660).\n- CVE-2017-16544: Fixed insufficient sanitization of filenames when autocompleting  (bsc#1069412).\n- CVE-2015-9261: Fixed huft_build misuses a pointer, causing segfaults (bsc#1102912).\n- CVE-2016-2147: Fixed out of bounds write (heap) due to integer underflow in udhcpc (bsc#970663).\n- CVE-2016-2148: Fixed heap-based buffer overflow in OPTION_6RD parsing (bsc#970662).\n- CVE-2016-6301: Fixed NTP server denial of service flaw (bsc#991940).\n- CVE-2017-15873: Fixed integer overflow in  get_next_block function in archival/libarchive/decompress_bunzip2.c (bsc#1064976).\n- CVE-2017-15874: Fixed integer overflow in archival/libarchive/decompress_unlzma (bsc#1064978).\n- CVE-2019-5747: Fixed out of bounds read in udhcp components (bsc#1121428).\n- CVE-2021-42373, CVE-2021-42374, CVE-2021-42375, CVE-2021-42376, CVE-2021-42377, CVE-2021-42378, CVE-2021-42379, CVE-2021-42380, CVE-2021-42381, CVE-2021-42382, CVE-2021-42383, CVE-2021-42384, CVE-2021-42385, CVE-2021-42386: v1.34.0 bugfixes (bsc#1192869).\n- CVE-2021-28831: Fixed invalid free or segmentation fault via malformed gzip data (bsc#1184522).\n- CVE-2018-20679: Fixed out of bounds read in udhcp (bsc#1121426).\n- CVE-2018-1000517: Fixed heap-based buffer overflow in the retrieve_file_data() (bsc#1099260).\n- CVE-2011-5325: Fixed tar directory traversal (bsc#951562).\n- CVE-2018-1000500: Fixed missing SSL certificate validation in wget (bsc#1099263).\n  \n- Update to 1.35.0\n  - awk: fix printf %%, fix read beyond end of buffer\n  - chrt: silence analyzer warning\n  - libarchive: remove duplicate forward declaration\n  - mount: 'mount -o rw ....' should not fall back to RO mount\n  - ps: fix -o pid=PID,args interpreting entire 'PID,args' as header\n  - tar: prevent malicious archives with long name sizes causing OOM\n  - udhcpc6: fix udhcp_find_option to actually find DHCP6 options\n  - xxd: fix -p -r\n  - support for new optoins added to basename, cpio, date, find, \n    mktemp, wget and others\n\n- Enable fdisk (jsc#CAR-16)\n\n- Update to 1.34.1:\n  * build system: use SOURCE_DATE_EPOCH for timestamp if available\n  * many bug fixes and new features\n  * touch: make FEATURE_TOUCH_NODEREF unconditional\n  \n- update to 1.33.1:\n  * httpd: fix sendfile\n  * ash: fix HISTFILE corruptio\n  * ash: fix unset variable pattern expansion\n  * traceroute: fix option parsing\n  * gunzip: fix for archive corruption\n\n- Update to version 1.33.0\n  - many bug fixes and new features\n\n- Update to version 1.32.1\n  - fixes a case where in ash, 'wait' never finishes. \n\n- prepare usrmerge (bsc#1029961)\n\n- Enable testsuite and package it for later rerun (for QA, jsc#CAR-15)\n\n- Update to version 1.31.1:\n  + Bug fix release. 1.30.1 has fixes for dc, ash (PS1 expansion\n    fix), hush, dpkg-deb, telnet and wget.\n- Changes from version 1.31.0:\n  + many bugfixes and new features.\n- Add busybox-no-stime.patch: stime() has been deprecated in glibc\n  2.31 and replaced with clock_settime().\n\n- update to 1.25.1:\n  * fixes for hush, gunzip, ip route, ntpd\n- includes changes from 1.25.0:\n  * many added and expanded implementations of command options\n- includes changes from 1.24.2:\n  * fixes for build system (static build with glibc fixed),\n    truncate, gunzip and unzip. \n\n- Update to version 1.24.1\n  * for a full list of changes see http://www.busybox.net/news.html\n- Refresh busybox.install.patch \n\n- Update to 1.23.2\n  * for a full list of changes see http://www.busybox.net/news.html\n- Cleaned up spec file with spec-cleaner\n- Refreshed patches\n\n- update to 1.22.1:\n  Many updates and fixes for most included tools, see\n  see http://www.busybox.net/news.html\n","modified":"2026-03-11T07:21:41.588017Z","published":"2022-11-28T10:23:47Z","related":["CVE-2011-5325","CVE-2014-9645","CVE-2015-9261","CVE-2016-2147","CVE-2016-2148","CVE-2016-6301","CVE-2017-15873","CVE-2017-15874","CVE-2017-16544","CVE-2018-1000500","CVE-2018-1000517","CVE-2018-20679","CVE-2019-5747","CVE-2021-28831","CVE-2021-42373","CVE-2021-42374","CVE-2021-42375","CVE-2021-42376","CVE-2021-42377","CVE-2021-42378","CVE-2021-42379","CVE-2021-42380","CVE-2021-42381","CVE-2021-42382","CVE-2021-42383","CVE-2021-42384","CVE-2021-42385","CVE-2021-42386"],"upstream":["CVE-2011-5325","CVE-2014-9645","CVE-2015-9261","CVE-2016-2147","CVE-2016-2148","CVE-2016-6301","CVE-2017-15873","CVE-2017-15874","CVE-2017-16544","CVE-2018-1000500","CVE-2018-1000517","CVE-2018-20679","CVE-2019-5747","CVE-2021-28831","CVE-2021-42373","CVE-2021-42374","CVE-2021-42375","CVE-2021-42376","CVE-2021-42377","CVE-2021-42378","CVE-2021-42379","CVE-2021-42380","CVE-2021-42381","CVE-2021-42382","CVE-2021-42383","CVE-2021-42384","CVE-2021-42385","CVE-2021-42386"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2022/suse-su-20224253-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1029961"},{"type":"REPORT","url":"https://bugzilla.suse.com/1064976"},{"type":"REPORT","url":"https://bugzilla.suse.com/1064978"},{"type":"REPORT","url":"https://bugzilla.suse.com/1069412"},{"type":"REPORT","url":"https://bugzilla.suse.com/1099260"},{"type":"REPORT","url":"https://bugzilla.suse.com/1099263"},{"type":"REPORT","url":"https://bugzilla.suse.com/1102912"},{"type":"REPORT","url":"https://bugzilla.suse.com/1121426"},{"type":"REPORT","url":"https://bugzilla.suse.com/1121428"},{"type":"REPORT","url":"https://bugzilla.suse.com/1184522"},{"type":"REPORT","url":"https://bugzilla.suse.com/1191514"},{"type":"REPORT","url":"https://bugzilla.suse.com/1192869"},{"type":"REPORT","url":"https://bugzilla.suse.com/914660"},{"type":"REPORT","url":"https://bugzilla.suse.com/951562"},{"type":"REPORT","url":"https://bugzilla.suse.com/970662"},{"type":"REPORT","url":"https://bugzilla.suse.com/970663"},{"type":"REPORT","url":"https://bugzilla.suse.com/991940"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2011-5325"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2014-9645"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2015-9261"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-2147"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-2148"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-6301"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-15873"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-15874"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-16544"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-1000500"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-1000517"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-20679"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-5747"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-28831"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-42373"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-42374"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-42375"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-42376"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-42377"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-42378"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-42379"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-42380"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-42381"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-42382"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-42383"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-42384"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-42385"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-42386"}],"affected":[{"package":{"name":"busybox","ecosystem":"SUSE:OpenStack Cloud 9","purl":"pkg:rpm/suse/busybox&distro=SUSE%20OpenStack%20Cloud%209"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.35.0-4.3.1"}]}],"ecosystem_specific":{"binaries":[{"busybox":"1.35.0-4.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:4253-1.json"}},{"package":{"name":"busybox","ecosystem":"SUSE:OpenStack Cloud Crowbar 9","purl":"pkg:rpm/suse/busybox&distro=SUSE%20OpenStack%20Cloud%20Crowbar%209"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.35.0-4.3.1"}]}],"ecosystem_specific":{"binaries":[{"busybox":"1.35.0-4.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:4253-1.json"}},{"package":{"name":"busybox","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 12 SP4","purl":"pkg:rpm/suse/busybox&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.35.0-4.3.1"}]}],"ecosystem_specific":{"binaries":[{"busybox":"1.35.0-4.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:4253-1.json"}},{"package":{"name":"busybox","ecosystem":"SUSE:Linux Enterprise Server 12 SP2-BCL","purl":"pkg:rpm/suse/busybox&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-BCL"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.35.0-4.3.1"}]}],"ecosystem_specific":{"binaries":[{"busybox":"1.35.0-4.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:4253-1.json"}},{"package":{"name":"busybox","ecosystem":"SUSE:Linux Enterprise Server 12 SP3-BCL","purl":"pkg:rpm/suse/busybox&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3-BCL"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.35.0-4.3.1"}]}],"ecosystem_specific":{"binaries":[{"busybox":"1.35.0-4.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:4253-1.json"}},{"package":{"name":"busybox","ecosystem":"SUSE:Linux Enterprise Server 12 SP4-LTSS","purl":"pkg:rpm/suse/busybox&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP4-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.35.0-4.3.1"}]}],"ecosystem_specific":{"binaries":[{"busybox":"1.35.0-4.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:4253-1.json"}},{"package":{"name":"busybox","ecosystem":"SUSE:Linux Enterprise Server 12 SP5","purl":"pkg:rpm/suse/busybox&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.35.0-4.3.1"}]}],"ecosystem_specific":{"binaries":[{"busybox":"1.35.0-4.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:4253-1.json"}},{"package":{"name":"busybox","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 12 SP5","purl":"pkg:rpm/suse/busybox&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.35.0-4.3.1"}]}],"ecosystem_specific":{"binaries":[{"busybox":"1.35.0-4.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:4253-1.json"}}],"schema_version":"1.7.5"}