Bug 1099260 - (CVE-2018-1000517) VUL-0: CVE-2018-1000517:busybox: Heap-based buffer overflow in the retrieve_file_data() function
(CVE-2018-1000517)
VUL-0: CVE-2018-1000517:busybox: Heap-based buffer overflow in the retrieve_...
Status: REOPENED
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P3 - Medium : Normal
: ---
Assigned To: Radoslav Kolev
Security Team bot
https://smash.suse.de/issue/208938/
CVSSv3:SUSE:CVE-2018-1000517:5.6:(AV...
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2018-06-27 08:47 UTC by Marcus Meissner
Modified: 2022-08-12 10:09 UTC (History)
6 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Marcus Meissner 2018-06-27 08:47:32 UTC
BusyBox project BusyBox wget version prior to commit
8e2174e9bd836e53c8b9c6e00d1bc6e2a718686e contains a Buffer Overflow
vulnerability in Busybox wget that can result in heap buffer overflow. This
attack appear to be exploitable via network connectivity. This vulnerability
appears to have been fixed in after commit
8e2174e9bd836e53c8b9c6e00d1bc6e2a718686e.

https://git.busybox.net/busybox/commit/?id=8e2174e9bd836e53c8b9c6e00d1bc6e2a718686e
Comment 3 Swamp Workflow Management 2021-10-27 13:29:33 UTC
openSUSE-SU-2021:3531-1: An update that fixes 5 vulnerabilities is now available.

Category: security (important)
Bug References: 1099260,1099263,1121426,1184522,951562
CVE References: CVE-2011-5325,CVE-2018-1000500,CVE-2018-1000517,CVE-2018-20679,CVE-2021-28831
JIRA References: 
Sources used:
openSUSE Leap 15.3 (src):    busybox-1.26.2-4.5.1, busybox-static-1.26.2-4.5.1
Comment 4 Swamp Workflow Management 2021-10-27 13:33:27 UTC
SUSE-SU-2021:3531-1: An update that fixes 5 vulnerabilities is now available.

Category: security (important)
Bug References: 1099260,1099263,1121426,1184522,951562
CVE References: CVE-2011-5325,CVE-2018-1000500,CVE-2018-1000517,CVE-2018-20679,CVE-2021-28831
JIRA References: 
Sources used:
SUSE Linux Enterprise Server for SAP 15-SP1 (src):    busybox-1.26.2-4.5.1, busybox-static-1.26.2-4.5.1
SUSE Linux Enterprise Server for SAP 15 (src):    busybox-1.26.2-4.5.1
SUSE Linux Enterprise Server 15-SP1-LTSS (src):    busybox-1.26.2-4.5.1, busybox-static-1.26.2-4.5.1
SUSE Linux Enterprise Server 15-SP1-BCL (src):    busybox-1.26.2-4.5.1, busybox-static-1.26.2-4.5.1
SUSE Linux Enterprise Server 15-LTSS (src):    busybox-1.26.2-4.5.1
SUSE Linux Enterprise Module for Basesystem 15-SP3 (src):    busybox-1.26.2-4.5.1, busybox-static-1.26.2-4.5.1
SUSE Linux Enterprise Module for Basesystem 15-SP2 (src):    busybox-1.26.2-4.5.1, busybox-static-1.26.2-4.5.1
SUSE Linux Enterprise High Performance Computing 15-SP1-LTSS (src):    busybox-1.26.2-4.5.1, busybox-static-1.26.2-4.5.1
SUSE Linux Enterprise High Performance Computing 15-SP1-ESPOS (src):    busybox-1.26.2-4.5.1, busybox-static-1.26.2-4.5.1
SUSE Linux Enterprise High Performance Computing 15-LTSS (src):    busybox-1.26.2-4.5.1
SUSE Linux Enterprise High Performance Computing 15-ESPOS (src):    busybox-1.26.2-4.5.1
SUSE Enterprise Storage 6 (src):    busybox-1.26.2-4.5.1, busybox-static-1.26.2-4.5.1
SUSE CaaS Platform 4.0 (src):    busybox-1.26.2-4.5.1, busybox-static-1.26.2-4.5.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 5 Swamp Workflow Management 2021-10-31 20:35:51 UTC
openSUSE-SU-2021:1408-1: An update that fixes 5 vulnerabilities is now available.

Category: security (important)
Bug References: 1099260,1099263,1121426,1184522,951562
CVE References: CVE-2011-5325,CVE-2018-1000500,CVE-2018-1000517,CVE-2018-20679,CVE-2021-28831
JIRA References: 
Sources used:
openSUSE Leap 15.2 (src):    busybox-1.26.2-lp152.5.3.1, busybox-static-1.26.2-lp152.5.3.1
Comment 10 Swamp Workflow Management 2022-01-20 14:19:35 UTC
openSUSE-SU-2022:0135-1: An update that fixes 27 vulnerabilities is now available.

Category: security (important)
Bug References: 1064976,1064978,1069412,1099260,1099263,1102912,1121426,1121428,1184522,1192869,951562,970662,970663,991940
CVE References: CVE-2011-5325,CVE-2015-9261,CVE-2016-2147,CVE-2016-2148,CVE-2016-6301,CVE-2017-15873,CVE-2017-15874,CVE-2017-16544,CVE-2018-1000500,CVE-2018-1000517,CVE-2018-20679,CVE-2019-5747,CVE-2021-28831,CVE-2021-42373,CVE-2021-42374,CVE-2021-42375,CVE-2021-42376,CVE-2021-42377,CVE-2021-42378,CVE-2021-42379,CVE-2021-42380,CVE-2021-42381,CVE-2021-42382,CVE-2021-42383,CVE-2021-42384,CVE-2021-42385,CVE-2021-42386
JIRA References: 
Sources used:
openSUSE Leap 15.3 (src):    busybox-1.34.1-4.9.1
Comment 11 Swamp Workflow Management 2022-01-20 14:24:21 UTC
SUSE-SU-2022:0135-1: An update that fixes 27 vulnerabilities is now available.

Category: security (important)
Bug References: 1064976,1064978,1069412,1099260,1099263,1102912,1121426,1121428,1184522,1192869,951562,970662,970663,991940
CVE References: CVE-2011-5325,CVE-2015-9261,CVE-2016-2147,CVE-2016-2148,CVE-2016-6301,CVE-2017-15873,CVE-2017-15874,CVE-2017-16544,CVE-2018-1000500,CVE-2018-1000517,CVE-2018-20679,CVE-2019-5747,CVE-2021-28831,CVE-2021-42373,CVE-2021-42374,CVE-2021-42375,CVE-2021-42376,CVE-2021-42377,CVE-2021-42378,CVE-2021-42379,CVE-2021-42380,CVE-2021-42381,CVE-2021-42382,CVE-2021-42383,CVE-2021-42384,CVE-2021-42385,CVE-2021-42386
JIRA References: 
Sources used:
SUSE Manager Server 4.1 (src):    busybox-1.34.1-4.9.1
SUSE Manager Retail Branch Server 4.1 (src):    busybox-1.34.1-4.9.1
SUSE Manager Proxy 4.1 (src):    busybox-1.34.1-4.9.1
SUSE Linux Enterprise Server for SAP 15-SP2 (src):    busybox-1.34.1-4.9.1
SUSE Linux Enterprise Server for SAP 15-SP1 (src):    busybox-1.34.1-4.9.1
SUSE Linux Enterprise Server for SAP 15 (src):    busybox-1.34.1-4.9.1
SUSE Linux Enterprise Server 15-SP2-LTSS (src):    busybox-1.34.1-4.9.1
SUSE Linux Enterprise Server 15-SP2-BCL (src):    busybox-1.34.1-4.9.1
SUSE Linux Enterprise Server 15-SP1-LTSS (src):    busybox-1.34.1-4.9.1
SUSE Linux Enterprise Server 15-SP1-BCL (src):    busybox-1.34.1-4.9.1
SUSE Linux Enterprise Server 15-LTSS (src):    busybox-1.34.1-4.9.1
SUSE Linux Enterprise Module for Basesystem 15-SP3 (src):    busybox-1.34.1-4.9.1
SUSE Linux Enterprise High Performance Computing 15-SP2-LTSS (src):    busybox-1.34.1-4.9.1
SUSE Linux Enterprise High Performance Computing 15-SP2-ESPOS (src):    busybox-1.34.1-4.9.1
SUSE Linux Enterprise High Performance Computing 15-SP1-LTSS (src):    busybox-1.34.1-4.9.1
SUSE Linux Enterprise High Performance Computing 15-SP1-ESPOS (src):    busybox-1.34.1-4.9.1
SUSE Linux Enterprise High Performance Computing 15-LTSS (src):    busybox-1.34.1-4.9.1
SUSE Linux Enterprise High Performance Computing 15-ESPOS (src):    busybox-1.34.1-4.9.1
SUSE Enterprise Storage 7 (src):    busybox-1.34.1-4.9.1
SUSE Enterprise Storage 6 (src):    busybox-1.34.1-4.9.1
SUSE CaaS Platform 4.0 (src):    busybox-1.34.1-4.9.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 12 Swamp Workflow Management 2022-02-14 14:23:21 UTC
SUSE-SU-2022:0135-2: An update that fixes 27 vulnerabilities is now available.

Category: security (important)
Bug References: 1064976,1064978,1069412,1099260,1099263,1102912,1121426,1121428,1184522,1192869,951562,970662,970663,991940
CVE References: CVE-2011-5325,CVE-2015-9261,CVE-2016-2147,CVE-2016-2148,CVE-2016-6301,CVE-2017-15873,CVE-2017-15874,CVE-2017-16544,CVE-2018-1000500,CVE-2018-1000517,CVE-2018-20679,CVE-2019-5747,CVE-2021-28831,CVE-2021-42373,CVE-2021-42374,CVE-2021-42375,CVE-2021-42376,CVE-2021-42377,CVE-2021-42378,CVE-2021-42379,CVE-2021-42380,CVE-2021-42381,CVE-2021-42382,CVE-2021-42383,CVE-2021-42384,CVE-2021-42385,CVE-2021-42386
JIRA References: 
Sources used:
SUSE Linux Enterprise Realtime Extension 15-SP2 (src):    busybox-1.34.1-4.9.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 13 Thomas Leroy 2022-05-06 09:03:58 UTC
Hi Ihno, could you please also submit to SUSE:SLE-11:Update and
SUSE:SLE-12:Update? :)
Comment 14 Swamp Workflow Management 2022-05-18 13:18:30 UTC
openSUSE-SU-2022:0135-1: An update that fixes 32 vulnerabilities is now available.

Category: security (important)
Bug References: 1064976,1064978,1069412,1099260,1099263,1102912,1121426,1121428,1184522,1192869,1198676,1198677,1198678,1198679,1198680,1198703,951562,970662,970663,991940
CVE References: CVE-2011-5325,CVE-2015-9261,CVE-2016-2147,CVE-2016-2148,CVE-2016-6301,CVE-2017-15873,CVE-2017-15874,CVE-2017-16544,CVE-2018-1000500,CVE-2018-1000517,CVE-2018-20679,CVE-2019-5747,CVE-2021-28831,CVE-2021-42373,CVE-2021-42374,CVE-2021-42375,CVE-2021-42376,CVE-2021-42377,CVE-2021-42378,CVE-2021-42379,CVE-2021-42380,CVE-2021-42381,CVE-2021-42382,CVE-2021-42383,CVE-2021-42384,CVE-2021-42385,CVE-2021-42386,CVE-2022-21465,CVE-2022-21471,CVE-2022-21487,CVE-2022-21488,CVE-2022-21491
JIRA References: 
Sources used:
openSUSE Leap 15.3 (src):    busybox-1.34.1-4.9.1, virtualbox-6.1.34-lp153.2.27.2, virtualbox-kmp-6.1.34-lp153.2.27.1
Comment 15 Robert Frohl 2022-08-04 09:31:01 UTC
(In reply to Thomas Leroy from comment #13)
> Hi Ihno, could you please also submit to SUSE:SLE-11:Update and
> SUSE:SLE-12:Update? :)

@Radoslav: ping