PublicDateAtUSN: 2017-02-09 Candidate: CVE-2016-2148 PublicDate: 2017-02-09 15:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2148 https://ubuntu.com/security/notices/USN-3935-1 Description: Heap-based buffer overflow in the DHCP client (udhcpc) in BusyBox before 1.25.0 allows remote attackers to have unspecified impact via vectors involving OPTION_6RD parsing. Ubuntu-Description: Notes: Bugs: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=818497 Priority: low Discovered-by: Nico Golde Assigned-to: mdeslaur CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H [9.8 CRITICAL] nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H [9.8 CRITICAL] Patches_busybox: upstream: https://git.busybox.net/busybox/commit/?id=352f79acbd759c14399e39baef21fc4ffe180ac2 Tags_busybox: universe-binary upstream_busybox: released (1:1.27.2-1) precise_busybox: not-affected (6RD code not present) precise/esm_busybox: not-affected (6RD code not present) trusty_busybox: released (1:1.21.0-1ubuntu1.4) trusty/esm_busybox: released (1:1.21.0-1ubuntu1.4) vivid/stable-phone-overlay_busybox: ignored (reached end-of-life) vivid/ubuntu-core_busybox: ignored (reached end-of-life) wily_busybox: ignored (reached end-of-life) xenial_busybox: released (1:1.22.0-15ubuntu1.4) esm-infra/xenial_busybox: released (1:1.22.0-15ubuntu1.4) yakkety_busybox: ignored (reached end-of-life) zesty_busybox: ignored (reached end-of-life) artful_busybox: ignored (reached end-of-life) bionic_busybox: not-affected (1:1.27.2-1ubuntu3) cosmic_busybox: not-affected (1:1.27.2-1ubuntu3) devel_busybox: not-affected (1:1.27.2-1ubuntu3)