Lucene search

K
osvGoogleOSV:USN-5244-2
HistoryMay 09, 2022 - 5:55 a.m.

dbus vulnerability

2022-05-0905:55:53
Google
osv.dev
6
dbus vulnerability ubuntu 18.04 lts 20.04 lts crash denial of service use-after-free username uid.

AI Score

7.3

Confidence

High

EPSS

0

Percentile

5.1%

USN-5244-1 fixed a vulnerability in DBus. This update provides
the corresponding update for Ubuntu 18.04 LTS and Ubuntu 20.04 LTS.

Original advisory details:

Daniel Onaca discovered that DBus contained a use-after-free vulnerability,
caused by the incorrect handling of usernames sharing the same UID. An
attacker could possibly use this issue to cause DBus to crash, resulting
in a denial of service.