Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2023:0096

Опубликовано: 12 янв. 2023
Источник: rocky
Оценка: Moderate

Описание

Moderate: dbus security update

D-Bus is a system for sending messages between applications. It is used both for the system-wide message bus service, and as a per-user-login-session messaging facility.

Security Fix(es):

  • dbus: dbus-daemon crashes when receiving message with incorrectly nested parentheses and curly brackets (CVE-2022-42010)

  • dbus: dbus-daemon can be crashed by messages with array length inconsistent with element type (CVE-2022-42011)

  • dbus: _dbus_marshal_byteswap doesn't process fds in messages with "foreign" endianness correctly (CVE-2022-42012)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 8

НаименованиеАрхитектураРелизRPM
dbusx86_6423.el8_7.1dbus-1.12.8-23.el8_7.1.x86_64.rpm
dbus-commonnoarch23.el8_7.1dbus-common-1.12.8-23.el8_7.1.noarch.rpm
dbus-daemonx86_6423.el8_7.1dbus-daemon-1.12.8-23.el8_7.1.x86_64.rpm
dbus-libsx86_6423.el8_7.1dbus-libs-1.12.8-23.el8_7.1.x86_64.rpm
dbus-toolsx86_6423.el8_7.1dbus-tools-1.12.8-23.el8_7.1.x86_64.rpm

Показывать по

Связанные уязвимости

suse-cvrf
больше 2 лет назад

Security update for dbus-1

suse-cvrf
больше 2 лет назад

Security update for dbus-1

suse-cvrf
больше 2 лет назад

Security update for dbus-1

suse-cvrf
больше 2 лет назад

Security update for dbus-1

CVSS3: 6.5
redos
почти 3 года назад

Множественные уязвимости D-Bus