CVE-2021-28831

Name
CVE-2021-28831
Description
decompress_gunzip.c in BusyBox through 1.32.1 mishandles the error bit on the huft_build result pointer, with a resultant invalid free or segmentation fault, via malformed gzip data.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Mailing List https://git.busybox.net/busybox/commit/?id=f25d254dfd4243698c31a4f3153d4ac72aa9e9bd
Mailing List https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZASBW7QRRLY5V2R44MQ4QQM4CZIDHM2U/
Mailing List https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/Z7ZIFKPRR32ZYA3WAA2NXFA3QHHOU6FJ/
FEDORA https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3UDQGJRECXFS5EZVDH2OI45FMO436AC4/
MLIST https://lists.debian.org/debian-lts-announce/2021/04/msg00001.html
GENTOO https://security.gentoo.org/glsa/202105-09
cve@mitre.org https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3UDQGJRECXFS5EZVDH2OI45FMO436AC4/
cve@mitre.org https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z7ZIFKPRR32ZYA3WAA2NXFA3QHHOU6FJ/
cve@mitre.org https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZASBW7QRRLY5V2R44MQ4QQM4CZIDHM2U/
af854a3a-2127-422b-91ae-364da2661108 https://security.netapp.com/advisory/ntap-20250509-0005/
af854a3a-2127-422b-91ae-364da2661108 https://lists.debian.org/debian-lts-announce/2025/01/msg00012.html

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:busybox:busybox:*:*:*:*:*:*:*:* busybox >= None <= 1.32.1
cpe:2.3:a:busybox:busybox:*:*:*:*:*:*:*:* busybox >= 1.32.0 <= 1.32.1

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
busybox edge-main 1.33.0-r5 None fixed
busybox edge-main 1.30.1-r2 None possibly vulnerable
busybox edge-main 1.29.3-r10 None possibly vulnerable
busybox edge-main 1.28.3-r2 None possibly vulnerable
busybox edge-main 1.27.2-r4 None possibly vulnerable
busybox 3.22-main 1.33.0-r5 None fixed
busybox 3.22-main 1.30.1-r2 None possibly vulnerable
busybox 3.22-main 1.29.3-r10 None possibly vulnerable
busybox 3.22-main 1.28.3-r2 None possibly vulnerable
busybox 3.22-main 1.27.2-r4 None possibly vulnerable
busybox 3.21-main 1.33.0-r5 None fixed
busybox 3.21-main 1.30.1-r2 None possibly vulnerable
busybox 3.21-main 1.29.3-r10 None possibly vulnerable
busybox 3.21-main 1.28.3-r2 None possibly vulnerable
busybox 3.21-main 1.27.2-r4 None possibly vulnerable
busybox 3.20-main 1.33.0-r5 None fixed
busybox 3.20-main 1.30.1-r2 None possibly vulnerable
busybox 3.20-main 1.29.3-r10 None possibly vulnerable
busybox 3.20-main 1.28.3-r2 None possibly vulnerable
busybox 3.20-main 1.27.2-r4 None possibly vulnerable
busybox 3.19-main 1.33.0-r5 None fixed
busybox 3.19-main 1.30.1-r2 None possibly vulnerable
busybox 3.19-main 1.29.3-r10 None possibly vulnerable
busybox 3.19-main 1.28.3-r2 None possibly vulnerable
busybox 3.19-main 1.27.2-r4 None possibly vulnerable
busybox 3.18-main 1.33.0-r5 None fixed
busybox 3.17-main 1.33.0-r5 None fixed
busybox 3.12-main 1.32.1-r4 None fixed
busybox 3.12-main 1.31.1-r22 Natanael Copa <ncopa@alpinelinux.org> fixed
busybox 3.12-main 1.31.1-r21 Natanael Copa <ncopa@alpinelinux.org> fixed
busybox 3.12-main 1.31.1-r20 Natanael Copa <ncopa@alpinelinux.org> fixed
busybox 3.11-main 1.31.1-r11 Natanael Copa <ncopa@alpinelinux.org> fixed
busybox 3.11-main 1.31.1-r10 Natanael Copa <ncopa@alpinelinux.org> fixed
busybox 3.10-main 1.30.1-r5 Natanael Copa <ncopa@alpinelinux.org> fixed