Vulnerabilities > CVE-2021-42376 - NULL Pointer Dereference vulnerability in multiple products

047910
CVSS 5.5 - MEDIUM
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
HIGH

Summary

A NULL pointer dereference in Busybox's hush applet leads to denial of service when processing a crafted shell command, due to missing validation after a \x03 delimiter character. This may be used for DoS under very rare conditions of filtered command input.

Vulnerable Configurations

Part Description Count
Application
Busybox
58
Application
Netapp
3
OS
Fedoraproject
2
OS
Netapp
7
Hardware
Netapp
7

Common Weakness Enumeration (CWE)