Security Fix(es):
An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authenticated attacker can cause dbus-daemon and other programs that use libdbus to crash when receiving a message with certain invalid type signatures.(CVE-2022-42010)
An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authenticated attacker can cause dbus-daemon and other programs that use libdbus to crash when receiving a message where an array length is inconsistent with the size of the element type.(CVE-2022-42011)
An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authenticated attacker can cause dbus-daemon and other programs that use libdbus to crash by sending a message with attached file descriptors in an unexpected format.(CVE-2022-42012)
{ "severity": "Medium" }
{ "src": [ "dbus-1.12.16-19.oe1.src.rpm" ], "x86_64": [ "dbus-debugsource-1.12.16-19.oe1.x86_64.rpm", "dbus-devel-1.12.16-19.oe1.x86_64.rpm", "dbus-1.12.16-19.oe1.x86_64.rpm", "dbus-x11-1.12.16-19.oe1.x86_64.rpm", "dbus-debuginfo-1.12.16-19.oe1.x86_64.rpm", "dbus-libs-1.12.16-19.oe1.x86_64.rpm", "dbus-tools-1.12.16-19.oe1.x86_64.rpm", "dbus-daemon-1.12.16-19.oe1.x86_64.rpm" ], "aarch64": [ "dbus-debuginfo-1.12.16-19.oe1.aarch64.rpm", "dbus-1.12.16-19.oe1.aarch64.rpm", "dbus-daemon-1.12.16-19.oe1.aarch64.rpm", "dbus-tools-1.12.16-19.oe1.aarch64.rpm", "dbus-debugsource-1.12.16-19.oe1.aarch64.rpm", "dbus-devel-1.12.16-19.oe1.aarch64.rpm", "dbus-x11-1.12.16-19.oe1.aarch64.rpm", "dbus-libs-1.12.16-19.oe1.aarch64.rpm" ], "noarch": [ "dbus-common-1.12.16-19.oe1.noarch.rpm", "dbus-help-1.12.16-19.oe1.noarch.rpm" ] }