CVE-2017-15873 | BusyBox 1.27.2 decompress_bunzip2.c get_next_block integer overflow (USN-3935-1 / EUVD-2017-7295)
A vulnerability classified as critical has been found in BusyBox 1.27.2. Affected is the function get_next_block in the library archival/libarchive/decompress_bunzip2.c. The manipulation leads to integer overflow.
This vulnerability is traded as CVE-2017-15873. Local access is required to approach this attack. There is no exploit available.
It is recommended to upgrade the affected component.