Busybox wget vulnerability
December 31, 2018 at 10:29
BusyBox project has fixed a vulnerability in BusyBox wget that may allow an attacker to execute arbitrary commands in the target system.
BusyBox combines tiny versions of many common UNIX utilities into a single small executable. It is generally used in embedded operating systems with limited resources.
Vulnerability coordination:
The vulnerability was found by Antti Levomäki, Christian Jalio, and Joonas Pihlaja from Forcepoint. NCSC-FI would like to thank Forcepoint and the BusyBox project for participating in the coordination.
Target of vulnerability
- BusyBox versions prior to 1.29.0
What is this about?
- Update BusyBox to the latest version.