{"@context":"https://spdx.org/rdf/3.0.1/spdx-context.jsonld","@graph":[{"type":"CreationInfo","@id":"_:CreationInfo0","created":"2024-09-26T21:31:12Z","createdBy":["http://spdx.org/spdxdocs/bitbake-addba517-4804-5ae3-87c2-0c3a1a5812ba/bitbake/agent/OpenEmbedded"],"createdUsing":["http://spdx.org/spdxdocs/bitbake-addba517-4804-5ae3-87c2-0c3a1a5812ba/bitbake/tool/oe-spdx-creator_1_0"],"specVersion":"3.0.1"},{"type":"CreationInfo","@id":"_:CreationInfo1","created":"2011-04-05T23:00:00Z","createdBy":["http://spdx.org/spdxdocs/bitbake-addba517-4804-5ae3-87c2-0c3a1a5812ba/bitbake/agent/OpenEmbedded"],"createdUsing":["http://spdx.org/spdxdocs/bitbake-addba517-4804-5ae3-87c2-0c3a1a5812ba/bitbake/tool/oe-spdx-creator_1_0"],"specVersion":"3.0.1"},{"type":"Organization","spdxId":"http://spdx.org/spdxdocs/bitbake-addba517-4804-5ae3-87c2-0c3a1a5812ba/bitbake/agent/OpenEmbedded","creationInfo":"_:CreationInfo1","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias"}],"name":"OpenEmbedded"},{"type":"Tool","spdxId":"http://spdx.org/spdxdocs/bitbake-addba517-4804-5ae3-87c2-0c3a1a5812ba/bitbake/tool/oe-spdx-creator_1_0","creationInfo":"_:CreationInfo1","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias"}],"name":"oe-spdx-creator 1.0"},{"type":"SpdxDocument","spdxId":"http://spdx.org/spdxdocs/busybox-88c2f534-0ecc-55ec-b418-e44fadbec098/c2317208b6580971d9cb5dae4c8b63f612f8065c347fd394c125f0da43fbaf65/document/package-busybox-udhcpc","creationInfo":"_:CreationInfo0","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias","https://rdf.openembedded.org/spdx/3.0/alias":"http://spdxdocs.org/openembedded-alias/doc/busybox/package-busybox-udhcpc/busybox/UNIHASH/document/package-busybox-udhcpc","https://rdf.openembedded.org/spdx/3.0/link-name":"9f1e4ddc65e9ecdb914c4092a172795d0a8425a4b282ff934eb5426780ceb8f0"}],"name":"package-busybox-udhcpc","profileConformance":["build","core","security","simpleLicensing","software"],"rootElement":["http://spdx.org/spdxdocs/busybox-88c2f534-0ecc-55ec-b418-e44fadbec098/c2317208b6580971d9cb5dae4c8b63f612f8065c347fd394c125f0da43fbaf65/package/busybox-udhcpc"]},{"type":"software_Package","spdxId":"http://spdx.org/spdxdocs/busybox-88c2f534-0ecc-55ec-b418-e44fadbec098/c2317208b6580971d9cb5dae4c8b63f612f8065c347fd394c125f0da43fbaf65/package/busybox-udhcpc","creationInfo":"_:CreationInfo0","description":"BusyBox combines tiny versions of many common UNIX utilities into a single small executable. It provides minimalist replacements for most of the utilities you usually find in GNU fileutils, shellutils, etc. The utilities in BusyBox generally have fewer options than their full-featured GNU cousins; however, the options that are included provide the expected functionality and behave very much like their GNU counterparts. BusyBox provides a fairly complete POSIX environment for any small or embedded system.","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias","https://rdf.openembedded.org/spdx/3.0/alias":"http://spdxdocs.org/openembedded-alias/by-doc-hash/9f1e4ddc65e9ecdb914c4092a172795d0a8425a4b282ff934eb5426780ceb8f0/busybox/UNIHASH/package/busybox-udhcpc"}],"externalIdentifier":[{"type":"ExternalIdentifier","externalIdentifierType":"cpe23","identifier":"cpe:2.3:*:*:busybox:1.37.0:*:*:*:*:*:*:*"}],"name":"busybox-udhcpc","summary":"Tiny versions of many common UNIX utilities in a single small executable","software_primaryPurpose":"install","software_homePage":"https://www.busybox.net","software_packageVersion":"1.37.0"},{"type":"software_File","spdxId":"http://spdx.org/spdxdocs/busybox-88c2f534-0ecc-55ec-b418-e44fadbec098/c2317208b6580971d9cb5dae4c8b63f612f8065c347fd394c125f0da43fbaf65/package/busybox-udhcpc/file/1","creationInfo":"_:CreationInfo0","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias","https://rdf.openembedded.org/spdx/3.0/alias":"http://spdxdocs.org/openembedded-alias/by-doc-hash/9f1e4ddc65e9ecdb914c4092a172795d0a8425a4b282ff934eb5426780ceb8f0/busybox/UNIHASH/package/busybox-udhcpc/file/1"}],"name":"etc/udhcpc.d/50default","verifiedUsing":[{"type":"Hash","algorithm":"sha256","hashValue":"01c3d71e7187a53d5adea159548c016663a1a3bed1a98970cda03ec3d87f8b3e"}]},{"type":"software_File","spdxId":"http://spdx.org/spdxdocs/busybox-88c2f534-0ecc-55ec-b418-e44fadbec098/c2317208b6580971d9cb5dae4c8b63f612f8065c347fd394c125f0da43fbaf65/package/busybox-udhcpc/file/2","creationInfo":"_:CreationInfo0","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias","https://rdf.openembedded.org/spdx/3.0/alias":"http://spdxdocs.org/openembedded-alias/by-doc-hash/9f1e4ddc65e9ecdb914c4092a172795d0a8425a4b282ff934eb5426780ceb8f0/busybox/UNIHASH/package/busybox-udhcpc/file/2"}],"name":"usr/share/udhcpc/default.script","verifiedUsing":[{"type":"Hash","algorithm":"sha256","hashValue":"61b6cb00935bfe02e72ba42f391dba731e5ecaf69a2edbb35aa0d0ea6f735807"}]},{"type":"Relationship","spdxId":"http://spdx.org/spdxdocs/busybox-88c2f534-0ecc-55ec-b418-e44fadbec098/c2317208b6580971d9cb5dae4c8b63f612f8065c347fd394c125f0da43fbaf65/relationship/63ee4c725312e7352aaff264825cc1be","creationInfo":"_:CreationInfo0","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias","https://rdf.openembedded.org/spdx/3.0/alias":"http://spdxdocs.org/openembedded-alias/by-doc-hash/9f1e4ddc65e9ecdb914c4092a172795d0a8425a4b282ff934eb5426780ceb8f0/busybox/UNIHASH/relationship/63ee4c725312e7352aaff264825cc1be"}],"from":"http://spdx.org/spdxdocs/busybox-88c2f534-0ecc-55ec-b418-e44fadbec098/c2317208b6580971d9cb5dae4c8b63f612f8065c347fd394c125f0da43fbaf65/package/busybox-udhcpc","relationshipType":"hasAssociatedVulnerability","to":["http://spdxdocs.org/openembedded-alias/by-doc-hash/8a02cf4130b79d0044bfb62b2e8adb03d1c4b38152c2e208ce7c08a1207e87f4/busybox/UNIHASH/vulnerability/CVE-2022-28391","http://spdxdocs.org/openembedded-alias/by-doc-hash/8a02cf4130b79d0044bfb62b2e8adb03d1c4b38152c2e208ce7c08a1207e87f4/busybox/UNIHASH/vulnerability/CVE-2023-39810","http://spdxdocs.org/openembedded-alias/by-doc-hash/8a02cf4130b79d0044bfb62b2e8adb03d1c4b38152c2e208ce7c08a1207e87f4/busybox/UNIHASH/vulnerability/CVE-2025-46394","http://spdxdocs.org/openembedded-alias/by-doc-hash/8a02cf4130b79d0044bfb62b2e8adb03d1c4b38152c2e208ce7c08a1207e87f4/busybox/UNIHASH/vulnerability/CVE-2025-60876"]},{"type":"Relationship","spdxId":"http://spdx.org/spdxdocs/busybox-88c2f534-0ecc-55ec-b418-e44fadbec098/c2317208b6580971d9cb5dae4c8b63f612f8065c347fd394c125f0da43fbaf65/relationship/687fab76e89dc2ac673cb15fbf544cad","creationInfo":"_:CreationInfo0","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias","https://rdf.openembedded.org/spdx/3.0/alias":"http://spdxdocs.org/openembedded-alias/by-doc-hash/9f1e4ddc65e9ecdb914c4092a172795d0a8425a4b282ff934eb5426780ceb8f0/busybox/UNIHASH/relationship/687fab76e89dc2ac673cb15fbf544cad"}],"from":"http://spdx.org/spdxdocs/busybox-88c2f534-0ecc-55ec-b418-e44fadbec098/c2317208b6580971d9cb5dae4c8b63f612f8065c347fd394c125f0da43fbaf65/package/busybox-udhcpc","relationshipType":"contains","to":["http://spdx.org/spdxdocs/busybox-88c2f534-0ecc-55ec-b418-e44fadbec098/c2317208b6580971d9cb5dae4c8b63f612f8065c347fd394c125f0da43fbaf65/package/busybox-udhcpc/file/1","http://spdx.org/spdxdocs/busybox-88c2f534-0ecc-55ec-b418-e44fadbec098/c2317208b6580971d9cb5dae4c8b63f612f8065c347fd394c125f0da43fbaf65/package/busybox-udhcpc/file/2"]},{"type":"Relationship","spdxId":"http://spdx.org/spdxdocs/busybox-88c2f534-0ecc-55ec-b418-e44fadbec098/c2317208b6580971d9cb5dae4c8b63f612f8065c347fd394c125f0da43fbaf65/relationship/7574ef7b950cfdb129514f18291bce42","creationInfo":"_:CreationInfo0","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias","https://rdf.openembedded.org/spdx/3.0/alias":"http://spdxdocs.org/openembedded-alias/by-doc-hash/9f1e4ddc65e9ecdb914c4092a172795d0a8425a4b282ff934eb5426780ceb8f0/busybox/UNIHASH/relationship/7574ef7b950cfdb129514f18291bce42"}],"from":"http://spdx.org/spdxdocs/busybox-88c2f534-0ecc-55ec-b418-e44fadbec098/c2317208b6580971d9cb5dae4c8b63f612f8065c347fd394c125f0da43fbaf65/package/busybox-udhcpc","relationshipType":"hasDeclaredLicense","to":["http://spdxdocs.org/openembedded-alias/by-doc-hash/8a02cf4130b79d0044bfb62b2e8adb03d1c4b38152c2e208ce7c08a1207e87f4/busybox/UNIHASH/license/3_27_0/GPL-2_0-only_AND_bzip2-1_0_6"]},{"type":"LifecycleScopedRelationship","spdxId":"http://spdx.org/spdxdocs/busybox-88c2f534-0ecc-55ec-b418-e44fadbec098/c2317208b6580971d9cb5dae4c8b63f612f8065c347fd394c125f0da43fbaf65/relationship/e91838ffe361f74c4818b162ccdad32c","creationInfo":"_:CreationInfo0","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias","https://rdf.openembedded.org/spdx/3.0/alias":"http://spdxdocs.org/openembedded-alias/by-doc-hash/9f1e4ddc65e9ecdb914c4092a172795d0a8425a4b282ff934eb5426780ceb8f0/busybox/UNIHASH/relationship/e91838ffe361f74c4818b162ccdad32c"}],"from":"http://spdxdocs.org/openembedded-alias/by-doc-hash/8a02cf4130b79d0044bfb62b2e8adb03d1c4b38152c2e208ce7c08a1207e87f4/busybox/UNIHASH/build/recipe","relationshipType":"hasOutput","to":["http://spdx.org/spdxdocs/busybox-88c2f534-0ecc-55ec-b418-e44fadbec098/c2317208b6580971d9cb5dae4c8b63f612f8065c347fd394c125f0da43fbaf65/package/busybox-udhcpc"],"scope":"build"},{"type":"security_VexFixedVulnAssessmentRelationship","spdxId":"http://spdx.org/spdxdocs/busybox-88c2f534-0ecc-55ec-b418-e44fadbec098/c2317208b6580971d9cb5dae4c8b63f612f8065c347fd394c125f0da43fbaf65/vex-fixed/20b8d7641b7ca5bbad646938a7b5e3c7","creationInfo":"_:CreationInfo0","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias","https://rdf.openembedded.org/spdx/3.0/alias":"http://spdxdocs.org/openembedded-alias/by-doc-hash/9f1e4ddc65e9ecdb914c4092a172795d0a8425a4b282ff934eb5426780ceb8f0/busybox/UNIHASH/vex-fixed/20b8d7641b7ca5bbad646938a7b5e3c7"}],"from":"http://spdxdocs.org/openembedded-alias/by-doc-hash/8a02cf4130b79d0044bfb62b2e8adb03d1c4b38152c2e208ce7c08a1207e87f4/busybox/UNIHASH/vulnerability/CVE-2025-60876","relationshipType":"fixedIn","to":["http://spdx.org/spdxdocs/busybox-88c2f534-0ecc-55ec-b418-e44fadbec098/c2317208b6580971d9cb5dae4c8b63f612f8065c347fd394c125f0da43fbaf65/package/busybox-udhcpc"],"security_vexVersion":"1.0.0"},{"type":"security_VexFixedVulnAssessmentRelationship","spdxId":"http://spdx.org/spdxdocs/busybox-88c2f534-0ecc-55ec-b418-e44fadbec098/c2317208b6580971d9cb5dae4c8b63f612f8065c347fd394c125f0da43fbaf65/vex-fixed/543aeab37a9744671fb9d0517dda3b05","creationInfo":"_:CreationInfo0","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias","https://rdf.openembedded.org/spdx/3.0/alias":"http://spdxdocs.org/openembedded-alias/by-doc-hash/9f1e4ddc65e9ecdb914c4092a172795d0a8425a4b282ff934eb5426780ceb8f0/busybox/UNIHASH/vex-fixed/543aeab37a9744671fb9d0517dda3b05"}],"from":"http://spdxdocs.org/openembedded-alias/by-doc-hash/8a02cf4130b79d0044bfb62b2e8adb03d1c4b38152c2e208ce7c08a1207e87f4/busybox/UNIHASH/vulnerability/CVE-2023-39810","relationshipType":"fixedIn","to":["http://spdx.org/spdxdocs/busybox-88c2f534-0ecc-55ec-b418-e44fadbec098/c2317208b6580971d9cb5dae4c8b63f612f8065c347fd394c125f0da43fbaf65/package/busybox-udhcpc"],"security_vexVersion":"1.0.0"},{"type":"security_VexFixedVulnAssessmentRelationship","spdxId":"http://spdx.org/spdxdocs/busybox-88c2f534-0ecc-55ec-b418-e44fadbec098/c2317208b6580971d9cb5dae4c8b63f612f8065c347fd394c125f0da43fbaf65/vex-fixed/580af7449ec08b250444c7108b8da68f","creationInfo":"_:CreationInfo0","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias","https://rdf.openembedded.org/spdx/3.0/alias":"http://spdxdocs.org/openembedded-alias/by-doc-hash/9f1e4ddc65e9ecdb914c4092a172795d0a8425a4b282ff934eb5426780ceb8f0/busybox/UNIHASH/vex-fixed/580af7449ec08b250444c7108b8da68f"}],"from":"http://spdxdocs.org/openembedded-alias/by-doc-hash/8a02cf4130b79d0044bfb62b2e8adb03d1c4b38152c2e208ce7c08a1207e87f4/busybox/UNIHASH/vulnerability/CVE-2025-46394","relationshipType":"fixedIn","to":["http://spdx.org/spdxdocs/busybox-88c2f534-0ecc-55ec-b418-e44fadbec098/c2317208b6580971d9cb5dae4c8b63f612f8065c347fd394c125f0da43fbaf65/package/busybox-udhcpc"],"security_vexVersion":"1.0.0"},{"type":"security_VexFixedVulnAssessmentRelationship","spdxId":"http://spdx.org/spdxdocs/busybox-88c2f534-0ecc-55ec-b418-e44fadbec098/c2317208b6580971d9cb5dae4c8b63f612f8065c347fd394c125f0da43fbaf65/vex-fixed/d5eadfbfd7b40d91f12a303e8a171944","creationInfo":"_:CreationInfo0","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias","https://rdf.openembedded.org/spdx/3.0/alias":"http://spdxdocs.org/openembedded-alias/by-doc-hash/9f1e4ddc65e9ecdb914c4092a172795d0a8425a4b282ff934eb5426780ceb8f0/busybox/UNIHASH/vex-fixed/d5eadfbfd7b40d91f12a303e8a171944"}],"from":"http://spdxdocs.org/openembedded-alias/by-doc-hash/8a02cf4130b79d0044bfb62b2e8adb03d1c4b38152c2e208ce7c08a1207e87f4/busybox/UNIHASH/vulnerability/CVE-2022-28391","relationshipType":"fixedIn","to":["http://spdx.org/spdxdocs/busybox-88c2f534-0ecc-55ec-b418-e44fadbec098/c2317208b6580971d9cb5dae4c8b63f612f8065c347fd394c125f0da43fbaf65/package/busybox-udhcpc"],"security_vexVersion":"1.0.0"}]}