Back to search
CVE-2018-1000500
Published: Jun 26, 2018
Modified: Jun 9, 2025
PUBLISHED
Description
Busybox contains a Missing SSL certificate validation vulnerability in The "busybox wget" applet that can result in arbitrary code execution. This attack appear to be exploitable via Simply download any file over HTTPS using "busybox wget https://compromised-domain.com/important-file".
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
http://lists.busybox.net/pipermail/busybox/2018-May/086462.html
x_refsource_MISC
USN-4531-1
vendor-advisory
x_refsource_UBUNTU
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now