Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <412BA242-7A24-4526-9B9F-156F3B33D515@entrust.com>
Date: Thu, 24 Apr 2025 17:14:19 +0000
From: Ian Norton <Ian.Norton@...rust.com>
To: "oss-security@...ts.openwall.com" <oss-security@...ts.openwall.com>
Subject: Re: [EXTERNAL] Re: vulnerabilities in busybox tar and
 cpio tools

On Thursday, 24 April 2025 at 17:16 Albert Veli <albert.veli@...il.com> wrote:
> On Wed, Apr 23, 2025 at 10:51 PM Salvatore Bonaccorso <carnil@...ian.org> wrote:
> > FTR, this one has assigned CVE-2025-46394

> From what I can tell the latest release is busybox-1.37.0. Are these fixed
> in this release? If not, do you have any link to patches I can apply to fix
> these issues?

I re-posted the patch for CVE-2025-46394 to https://lists.busybox.net/pipermail/busybox/2025-April/091461.html

I was sceptical about the isatty() call but it was requested by others on the list

--
Ian



Any email and files/attachments transmitted with it are intended solely for the use of the individual or entity to whom they are addressed. If this message has been sent to you in error, you must not copy, distribute or disclose of the information it contains. Please notify Entrust immediately and delete the message from your system.

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.