Security Fix(es):
An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authenticated attacker can cause dbus-daemon and other programs that use libdbus to crash when receiving a message with certain invalid type signatures.(CVE-2022-42010)
An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authenticated attacker can cause dbus-daemon and other programs that use libdbus to crash when receiving a message where an array length is inconsistent with the size of the element type.(CVE-2022-42011)
An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authenticated attacker can cause dbus-daemon and other programs that use libdbus to crash by sending a message with attached file descriptors in an unexpected format.(CVE-2022-42012)
{
"severity": "Medium"
}{
"noarch": [
"dbus-common-1.12.16-20.oe1.noarch.rpm",
"dbus-help-1.12.16-20.oe1.noarch.rpm"
],
"src": [
"dbus-1.12.16-20.oe1.src.rpm"
],
"aarch64": [
"dbus-devel-1.12.16-20.oe1.aarch64.rpm",
"dbus-libs-1.12.16-20.oe1.aarch64.rpm",
"dbus-debugsource-1.12.16-20.oe1.aarch64.rpm",
"dbus-daemon-1.12.16-20.oe1.aarch64.rpm",
"dbus-tools-1.12.16-20.oe1.aarch64.rpm",
"dbus-x11-1.12.16-20.oe1.aarch64.rpm",
"dbus-debuginfo-1.12.16-20.oe1.aarch64.rpm",
"dbus-1.12.16-20.oe1.aarch64.rpm"
],
"x86_64": [
"dbus-libs-1.12.16-20.oe1.x86_64.rpm",
"dbus-1.12.16-20.oe1.x86_64.rpm",
"dbus-x11-1.12.16-20.oe1.x86_64.rpm",
"dbus-debugsource-1.12.16-20.oe1.x86_64.rpm",
"dbus-daemon-1.12.16-20.oe1.x86_64.rpm",
"dbus-devel-1.12.16-20.oe1.x86_64.rpm",
"dbus-debuginfo-1.12.16-20.oe1.x86_64.rpm",
"dbus-tools-1.12.16-20.oe1.x86_64.rpm"
]
}