First published: Sun Oct 09 2022(Updated: )
An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authenticated attacker can cause dbus-daemon and other programs that use libdbus to crash by sending a message with attached file descriptors in an unexpected format.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
D-bus Project D-bus | <1.12.24 | |
D-bus Project D-bus | >=1.13.0<1.14.4 | |
D-bus Project D-bus | >=1.15.0<1.15.2 | |
Fedoraproject Fedora | =35 | |
Fedoraproject Fedora | =36 | |
Fedoraproject Fedora | =37 | |
Freedesktop Dbus | <1.12.24 | |
Freedesktop Dbus | >=1.13.0<1.14.4 | |
Freedesktop Dbus | >=1.15.0<1.15.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-42012 is a vulnerability discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2.
CVE-2022-42012 allows an authenticated attacker to crash dbus-daemon and other programs that use libdbus by sending a message with attached file descriptors in an unexpected format.
CVE-2022-42012 has a severity rating of 6.5, which is considered medium.
D-Bus versions before 1.12.24, between 1.13.0 and 1.14.4, and between 1.15.0 and 1.15.2 are affected by CVE-2022-42012.
To fix CVE-2022-42012, update D-Bus to version 1.12.24 or higher, 1.14.4 or higher, or 1.15.2 or higher.