PT-2026-78263 · Busybox · Busybox
CVSS v3.1
3.3
Low
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
BusyBox versions prior to 1.30.1
Description
A null pointer dereference occurs in the
FEATURE WGET TIMEOUT handler within the networking/wget.c file. This issue is triggered by the manipulation of the -T argument and requires local access to be exploited.Recommendations
Apply patch 83a40bf7a93c8ac093d33ab452222dd5b9eb57ff to versions prior to 1.30.1.
Exploit
Fix
NULL Pointer Dereference
Improper Resource Release
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Busybox