ALSA-2023:0335

Source
https://errata.almalinux.org/9/ALSA-2023-0335.html
Import Source
https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux9/ALSA-2023:0335.json
JSON Data
https://api.osv.dev/v1/vulns/ALSA-2023:0335
Related
Published
2023-01-23T00:00:00Z
Modified
2023-01-24T17:21:12Z
Summary
Moderate: dbus security update
Details

D-Bus is a system for sending messages between applications. It is used both for the system-wide message bus service, and as a per-user-login-session messaging facility.

Security Fix(es):

  • dbus: dbus-daemon crashes when receiving message with incorrectly nested parentheses and curly brackets (CVE-2022-42010)
  • dbus: dbus-daemon can be crashed by messages with array length inconsistent with element type (CVE-2022-42011)
  • dbus: _dbus_marshal_byteswap doesn't process fds in messages with "foreign" endianness correctly (CVE-2022-42012)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

References

Affected packages

AlmaLinux:9 / dbus

Package

Name
dbus

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:1.12.20-7.el9_1

AlmaLinux:9 / dbus-common

Package

Name
dbus-common

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:1.12.20-7.el9_1

AlmaLinux:9 / dbus-daemon

Package

Name
dbus-daemon

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:1.12.20-7.el9_1

AlmaLinux:9 / dbus-devel

Package

Name
dbus-devel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:1.12.20-7.el9_1

AlmaLinux:9 / dbus-libs

Package

Name
dbus-libs

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:1.12.20-7.el9_1

AlmaLinux:9 / dbus-tools

Package

Name
dbus-tools

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:1.12.20-7.el9_1

AlmaLinux:9 / dbus-x11

Package

Name
dbus-x11

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:1.12.20-7.el9_1