Lucene search

K
redhatRedHatRHSA-2023:0096
HistoryJan 12, 2023 - 8:25 a.m.

(RHSA-2023:0096) Moderate: dbus security update

2023-01-1208:25:26
access.redhat.com
41
d-bus system messaging
security fix
dbus-daemon crashes
nested parentheses
curly brackets
array length inconsistency
_dbus_marshal_byteswap
foreign endianness.

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

EPSS

0.002

Percentile

56.6%

D-Bus is a system for sending messages between applications. It is used both for the system-wide message bus service, and as a per-user-login-session messaging facility.

Security Fix(es):

  • dbus: dbus-daemon crashes when receiving message with incorrectly nested parentheses and curly brackets (CVE-2022-42010)

  • dbus: dbus-daemon can be crashed by messages with array length inconsistent with element type (CVE-2022-42011)

  • dbus: _dbus_marshal_byteswap doesn’t process fds in messages with “foreign” endianness correctly (CVE-2022-42012)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

EPSS

0.002

Percentile

56.6%