Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-42012

Опубликовано: 05 окт. 2022
Источник: redhat
CVSS3: 6.5

Описание

An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authenticated attacker can cause dbus-daemon and other programs that use libdbus to crash by sending a message with attached file descriptors in an unexpected format.

A vulnerability found in D-bus. This flaw allows an authenticated attacker to cause dbus-daemon and other programs that use libdbus to crash by sending a message with attached file descriptors in an unexpected format.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6dbusOut of support scope
Red Hat Enterprise Linux 7dbusOut of support scope
Red Hat Enterprise Linux 8dbusFixedRHSA-2023:009612.01.2023
Red Hat Enterprise Linux 8dbusFixedRHSA-2023:009612.01.2023
Red Hat Enterprise Linux 8.6 Extended Update SupportdbusFixedRHSA-2022:881206.12.2022
Red Hat Enterprise Linux 9dbusFixedRHSA-2023:033523.01.2023
Red Hat Enterprise Linux 9dbusFixedRHSA-2023:033523.01.2023
Red Hat Enterprise Linux 9.0 Extended Update SupportdbusFixedRHSA-2022:897713.12.2022

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=2133618dbus: `_dbus_marshal_byteswap` doesn't process fds in messages with "foreign" endianness correctly

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
почти 3 года назад

An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authenticated attacker can cause dbus-daemon and other programs that use libdbus to crash by sending a message with attached file descriptors in an unexpected format.

CVSS3: 6.5
nvd
почти 3 года назад

An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authenticated attacker can cause dbus-daemon and other programs that use libdbus to crash by sending a message with attached file descriptors in an unexpected format.

CVSS3: 6.5
msrc
почти 3 года назад

Описание отсутствует

CVSS3: 6.5
debian
почти 3 года назад

An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x bef ...

CVSS3: 6.5
github
почти 3 года назад

An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authenticated attacker can cause dbus-daemon and other programs that use libdbus to crash by sending a message with attached file descriptors in an unexpected format.

6.5 Medium

CVSS3