New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 880786 link

Starred by 1 user

Issue metadata

Status: Fixed
Owner:
Last visit > 30 days ago
Closed: Sep 17
Components:
EstimatedDays: ----
NextAction: ----
OS: Chrome
Pri: 1
Type: Bug-Security

Blocked on:
issue 879543



Sign in to add a comment

CrOS: Vulnerability reported in sys-apps/busybox

Project Member Reported by vomit.go...@appspot.gserviceaccount.com, Sep 5

Issue description

Automated analysis has detected that the following third party packages have had vulnerabilities publicly reported. 

NOTE: There may be several bugs listed below - in almost all cases, all bugs can be quickly addressed by upgrading to the latest version of the package.

Package Name: sys-apps/busybox
Package Version: [cpe:/a:busybox:busybox:1.27.2]

Advisory: CVE-2018-1000500
  Details: https://vomit.googleplex.com/advisory?id=CVE/CVE-2018-1000500
  CVSS severity score: 6.8/10.0
  Confidence: high
  Description:

Busybox contains a Missing SSL certificate validation vulnerability in The "busybox wget" applet that can result in arbitrary code execution. This attack appear to be exploitable via Simply download any file over HTTPS using "busybox wget https://compromised-domain.com/important-file".


 
Blockedon: 879543
Components: OS>Packages
Labels: Security_Severity-Medium
we're going to upgrade as part of  issue 880786 , so we'll just close this when that one closes
Owner: yunlian@chromium.org
Status: Assigned (was: Untriaged)
Project Member

Comment 3 by sheriffbot@chromium.org, Sep 6

Labels: -Pri-2 Pri-1
Status: Fixed (was: Assigned)
Fixed as per the blocking bug.
Project Member

Comment 5 by sheriffbot@chromium.org, Sep 18

Labels: -Restrict-View-SecurityTeam Restrict-View-SecurityNotify
Project Member

Comment 6 by sheriffbot@chromium.org, Dec 25

Labels: -Restrict-View-SecurityNotify allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment