Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-42012

Опубликовано: 05 окт. 2022
Источник: redhat
CVSS3: 6.5

Описание

An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authenticated attacker can cause dbus-daemon and other programs that use libdbus to crash by sending a message with attached file descriptors in an unexpected format.

A vulnerability found in D-bus. This flaw allows an authenticated attacker to cause dbus-daemon and other programs that use libdbus to crash by sending a message with attached file descriptors in an unexpected format.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6dbusOut of support scope
Red Hat Enterprise Linux 7dbusOut of support scope
Red Hat Enterprise Linux 8dbusFixedRHSA-2023:009612.01.2023
Red Hat Enterprise Linux 8dbusFixedRHSA-2023:009612.01.2023
Red Hat Enterprise Linux 8.6 Extended Update SupportdbusFixedRHSA-2022:881206.12.2022
Red Hat Enterprise Linux 9dbusFixedRHSA-2023:033523.01.2023
Red Hat Enterprise Linux 9dbusFixedRHSA-2023:033523.01.2023
Red Hat Enterprise Linux 9.0 Extended Update SupportdbusFixedRHSA-2022:897713.12.2022

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=2133618dbus: `_dbus_marshal_byteswap` doesn't process fds in messages with "foreign" endianness correctly

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 3 лет назад

An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authenticated attacker can cause dbus-daemon and other programs that use libdbus to crash by sending a message with attached file descriptors in an unexpected format.

CVSS3: 6.5
nvd
около 3 лет назад

An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authenticated attacker can cause dbus-daemon and other programs that use libdbus to crash by sending a message with attached file descriptors in an unexpected format.

CVSS3: 6.5
msrc
около 3 лет назад

An issue was discovered in D-Bus before 1.12.24 1.13.x and 1.14.x before 1.14.4 and 1.15.x before 1.15.2. An authenticated attacker can cause dbus-daemon and other programs that use libdbus to crash by sending a message with attached file descriptors in an unexpected format.

CVSS3: 6.5
debian
около 3 лет назад

An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x bef ...

CVSS3: 6.5
github
около 3 лет назад

An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authenticated attacker can cause dbus-daemon and other programs that use libdbus to crash by sending a message with attached file descriptors in an unexpected format.

6.5 Medium

CVSS3