[Debian] Medium CVE: CVE-2022-42010/CVE-2022-42011/CVE-2022-42012: dbus: multiple CVEs

Bug #2021465 reported by Yue Tao
256
This bug affects 1 person
Affects Status Importance Assigned to Milestone
StarlingX
Fix Released
Medium
Li Zhou

Bug Description

CVE-2022-42010: https://nvd.nist.gov/vuln/detail/CVE-2022-42010

An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authenticated attacker can cause dbus-daemon and other programs that use libdbus to crash when receiving a message with certain invalid type signatures.

CVE-2022-42011: https://nvd.nist.gov/vuln/detail/CVE-2022-42011

An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authenticated attacker can cause dbus-daemon and other programs that use libdbus to crash when receiving a message where an array length is inconsistent with the size of the element type.

CVE-2022-42012: https://nvd.nist.gov/vuln/detail/CVE-2022-42012

An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authenticated attacker can cause dbus-daemon and other programs that use libdbus to crash by sending a message with attached file descriptors in an unexpected format.

Base Score: Medium

References:

https://www.debian.org/security/2022/dsa-5250

https://security-tracker.debian.org/tracker/CVE-2022-42010

https://security-tracker.debian.org/tracker/CVE-2022-42011

https://security-tracker.debian.org/tracker/CVE-2022-42012

['dbus_1.12.20-2_amd64.deb===>dbus_1.12.24-0+deb11u1_amd64.deb', 'dbus-user-session_1.12.20-2_amd64.deb===>dbus-user-session_1.12.24-0+deb11u1_amd64.deb', 'libdbus-1-3_1.12.20-2_amd64.deb===>libdbus-1-3_1.12.24-0+deb11u1_amd64.deb']

Yue Tao (wrytao)
tags: added: stx.9.0 stx.security
Li Zhou (lzhou2)
Changed in starlingx:
assignee: nobody → Li Zhou (lzhou2)
Revision history for this message
Ghada Khalil (gkhalil) wrote :
Changed in starlingx:
status: Triaged → Fix Released
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.