There is a stack overflow vulnerability in ash.c:6030 in busybox before 1.35. In the environment of Internet of Vehicles, this vulnerability can be executed from command to arbitrary code execution.
No PoCs from references.
- https://github.com/ChrisAdkin8/Nomad-Job-Vulnerability-Tagging
- https://github.com/nqminds/SBOM-GAP
- https://github.com/nqminds/sbom-cli
- https://github.com/tquizzle/clamav-alpine