[Bug 15829] New: Memory vulnerabilities in awk and sed

bugzilla at busybox.net bugzilla at busybox.net
Thu Oct 26 14:08:57 UTC 2023


https://bugs.busybox.net/show_bug.cgi?id=15829

            Bug ID: 15829
           Summary: Memory vulnerabilities in awk and sed
           Product: Busybox
           Version: unspecified
          Hardware: All
                OS: Linux
            Status: NEW
          Severity: critical
          Priority: P5
         Component: Other
          Assignee: unassigned at busybox.net
          Reporter: tuba at ece.ufl.edu
                CC: busybox-cvs at busybox.net
  Target Milestone: ---

Hello,

Our research group has found some exploitable vulnerabilities in BusyBox 1.36.0
using the AFL fuzzer. We used the defconfig as well as several configuration
files generated by our own tool. We will provide all the details. However, we
wonder if this is a secure channel to discuss the vulnerabilities. Please let
us know. Thanks.

Tuba

-- 
You are receiving this mail because:
You are on the CC list for the bug.


More information about the busybox-cvs mailing list