Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2021-28831
Description:decompress_gunzip.c in BusyBox through 1.32.1 mishandles the error bit on the huft_build result pointer, with a resultant invalid free or segmentation fault, via malformed gzip data.
Test IDs: 1.3.6.1.4.1.25623.1.1.10.2021.0310   1.3.6.1.4.1.25623.1.0.879318   1.3.6.1.4.1.25623.1.0.818253   1.3.6.1.4.1.25623.1.0.892614   1.3.6.1.4.1.25623.1.0.879280   1.3.6.1.4.1.25623.1.1.4.2022.3959.1   1.3.6.1.4.1.25623.1.0.879303   1.3.6.1.4.1.25623.1.1.12.2022.5179.2   1.3.6.1.4.1.25623.1.1.2.2021.2522   1.3.6.1.4.1.25623.1.0.818254   1.3.6.1.4.1.25623.1.1.2.2021.2546  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2021-28831
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3UDQGJRECXFS5EZVDH2OI45FMO436AC4/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/Z7ZIFKPRR32ZYA3WAA2NXFA3QHHOU6FJ/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZASBW7QRRLY5V2R44MQ4QQM4CZIDHM2U/
https://security.gentoo.org/glsa/202105-09
https://git.busybox.net/busybox/commit/?id=f25d254dfd4243698c31a4f3153d4ac72aa9e9bd
https://lists.debian.org/debian-lts-announce/2021/04/msg00001.html




© 1998-2025 E-Soft Inc. All rights reserved.