Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-42011

Опубликовано: 05 окт. 2022
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authenticated attacker can cause dbus-daemon and other programs that use libdbus to crash when receiving a message where an array length is inconsistent with the size of the element type.

A vulnerability found in D-bus. This flaw allows an authenticated attacker to cause dbus-daemon and other programs that use libdbus to crash when receiving a message whose array length is inconsistent with the size of the element type.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6dbusOut of support scope
Red Hat Enterprise Linux 7dbusOut of support scope
Red Hat Enterprise Linux 8dbusFixedRHSA-2023:009612.01.2023
Red Hat Enterprise Linux 8dbusFixedRHSA-2023:009612.01.2023
Red Hat Enterprise Linux 8.6 Extended Update SupportdbusFixedRHSA-2022:881206.12.2022
Red Hat Enterprise Linux 9dbusFixedRHSA-2023:033523.01.2023
Red Hat Enterprise Linux 9dbusFixedRHSA-2023:033523.01.2023
Red Hat Enterprise Linux 9.0 Extended Update SupportdbusFixedRHSA-2022:897713.12.2022

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=2133617dbus: dbus-daemon can be crashed by messages with array length inconsistent with element type

EPSS

Процентиль: 26%
0.00085
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
почти 3 года назад

An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authenticated attacker can cause dbus-daemon and other programs that use libdbus to crash when receiving a message where an array length is inconsistent with the size of the element type.

CVSS3: 6.5
nvd
почти 3 года назад

An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authenticated attacker can cause dbus-daemon and other programs that use libdbus to crash when receiving a message where an array length is inconsistent with the size of the element type.

CVSS3: 6.5
msrc
почти 3 года назад

Описание отсутствует

CVSS3: 6.5
debian
почти 3 года назад

An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x bef ...

CVSS3: 6.5
github
почти 3 года назад

An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authenticated attacker can cause dbus-daemon and other programs that use libdbus to crash when receiving a message where an array length is inconsistent with the size of the element type.

EPSS

Процентиль: 26%
0.00085
Низкий

6.5 Medium

CVSS3

Уязвимость CVE-2022-42011