BusyBox Project wget Heap Buffer Overflow

Strike ID:
E18-8vnp1
CVSS:
9.8 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
False Positive:
f
Variants:
1
Year:
2018

Description

This strike exploits a heap buffer overflow vulnerability found in BusyBox wget module. The vulnerability is due to insufficient validation of chunk length while parsing server response. Remote attackers can exploit this vulnerability by crafting a malicious HTTP response packet with chunked transfer encoding. Successful exploitation could lead to code execution on the target system.

CVE

References