{"id":34488,"date":"2022-12-06T20:20:51","date_gmt":"2022-12-06T17:20:51","guid":{"rendered":"https:\/\/packetstormsecurity.com\/files\/170106\/RHSA-2022-8812-01.txt"},"modified":"2022-12-12T11:11:28","modified_gmt":"2022-12-12T07:41:28","slug":"red-hat-security-advisory-2022-8812-01-dbus","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/red-hat-security-advisory-2022-8812-01-dbus\/","title":{"rendered":"Red Hat Security Advisory 2022-8812-01 dbus"},"content":{"rendered":"<p dir=\"ltr\">&#8212;&#8211;BEGIN PGP SIGNED MESSAGE&#8212;&#8211;<br \/>\nHash: SHA256<\/p>\n<p dir=\"ltr\">====================================================================<br \/>\nRed Hat Security Advisory<\/p>\n<p dir=\"ltr\">Synopsis: Moderate: dbus security update<br \/>\nAdvisory ID: RHSA-2022:8812-01<br \/>\nProduct: Red Hat Enterprise Linux<br \/>\nAdvisory URL: https:\/\/access.redhat.com\/errata\/RHSA-2022:8812<br \/>\nIssue date: 2022-12-06<br \/>\nCVE Names: CVE-2022-42010 CVE-2022-42011 CVE-2022-42012<br \/>\n====================================================================<br \/>\n1. Summary:<\/p>\n<p dir=\"ltr\">An update for dbus is now available for Red Hat Enterprise Linux 8.6<br \/>\nExtended Update Support.<\/p>\n<p dir=\"ltr\">Red Hat Product Security has rated this update as having a security impact<br \/>\nof Moderate. A Common Vulnerability Scoring System (CVSS) base score, which<br \/>\ngives a detailed severity rating, is available for each vulnerability from<br \/>\nthe CVE link(s) in the References section.<\/p>\n<p dir=\"ltr\">2. Relevant releases\/architectures:<\/p>\n<p dir=\"ltr\">Red Hat Enterprise Linux AppStream EUS (v.8.6) &#8211; aarch64, ppc64le, s390x, x86_64<br \/>\nRed Hat Enterprise Linux BaseOS EUS (v.8.6) &#8211; aarch64, noarch, ppc64le, s390x, x86_64<\/p>\n<p dir=\"ltr\">3. Description:<\/p>\n<p dir=\"ltr\">D-Bus is a system for sending messages between applications. It is used<br \/>\nboth for the system-wide message bus service, and as a<br \/>\nper-user-login-session messaging facility.<\/p>\n<p dir=\"ltr\">Security Fix(es):<\/p>\n<p dir=\"ltr\">* dbus: dbus-daemon crashes when receiving message with incorrectly nested<br \/>\nparentheses and curly brackets (CVE-2022-42010)<\/p>\n<p dir=\"ltr\">* dbus: dbus-daemon can be crashed by messages with array length<br \/>\ninconsistent with element type (CVE-2022-42011)<\/p>\n<p dir=\"ltr\">* dbus: `_dbus_marshal_byteswap` doesn&#8217;t process fds in messages with<br \/>\n&#8220;foreign&#8221; endianness correctly (CVE-2022-42012)<\/p>\n<p dir=\"ltr\">For more details about the security issue(s), including the impact, a CVSS<br \/>\nscore, acknowledgments, and other related information, refer to the CVE<br \/>\npage(s) listed in the References section.<\/p>\n<p dir=\"ltr\">4. Solution:<\/p>\n<p dir=\"ltr\">For details on how to apply this update, which includes the changes<br \/>\ndescribed in this advisory, refer to:<\/p>\n<p dir=\"ltr\">https:\/\/access.redhat.com\/articles\/11258<\/p>\n<p dir=\"ltr\">For the update to take effect, all running instances of dbus-daemon and all<br \/>\nrunning applications using the libdbus library must be restarted, or the<br \/>\nsystem rebooted.<\/p>\n<p dir=\"ltr\">5. Bugs fixed (https:\/\/bugzilla.redhat.com\/):<\/p>\n<p dir=\"ltr\">2133616 &#8211; CVE-2022-42010 dbus: dbus-daemon crashes when receiving message with incorrectly nested parentheses and curly brackets<br \/>\n2133617 &#8211; CVE-2022-42011 dbus: dbus-daemon can be crashed by messages with array length inconsistent with element type<br \/>\n2133618 &#8211; CVE-2022-42012 dbus: `_dbus_marshal_byteswap` doesn&#8217;t process fds in messages with &#8220;foreign&#8221; endianness correctly<\/p>\n<p dir=\"ltr\">6. Package List:<\/p>\n<p dir=\"ltr\">Red Hat Enterprise Linux AppStream EUS (v.8.6):<\/p>\n<p dir=\"ltr\">aarch64:<br \/>\ndbus-daemon-debuginfo-1.12.8-18.el8_6.2.aarch64.rpm<br \/>\ndbus-debuginfo-1.12.8-18.el8_6.2.aarch64.rpm<br \/>\ndbus-debugsource-1.12.8-18.el8_6.2.aarch64.rpm<br \/>\ndbus-devel-1.12.8-18.el8_6.2.aarch64.rpm<br \/>\ndbus-libs-debuginfo-1.12.8-18.el8_6.2.aarch64.rpm<br \/>\ndbus-tests-debuginfo-1.12.8-18.el8_6.2.aarch64.rpm<br \/>\ndbus-tools-debuginfo-1.12.8-18.el8_6.2.aarch64.rpm<br \/>\ndbus-x11-1.12.8-18.el8_6.2.aarch64.rpm<br \/>\ndbus-x11-debuginfo-1.12.8-18.el8_6.2.aarch64.rpm<\/p>\n<p dir=\"ltr\">ppc64le:<br \/>\ndbus-daemon-debuginfo-1.12.8-18.el8_6.2.ppc64le.rpm<br \/>\ndbus-debuginfo-1.12.8-18.el8_6.2.ppc64le.rpm<br \/>\ndbus-debugsource-1.12.8-18.el8_6.2.ppc64le.rpm<br \/>\ndbus-devel-1.12.8-18.el8_6.2.ppc64le.rpm<br \/>\ndbus-libs-debuginfo-1.12.8-18.el8_6.2.ppc64le.rpm<br \/>\ndbus-tests-debuginfo-1.12.8-18.el8_6.2.ppc64le.rpm<br \/>\ndbus-tools-debuginfo-1.12.8-18.el8_6.2.ppc64le.rpm<br \/>\ndbus-x11-1.12.8-18.el8_6.2.ppc64le.rpm<br \/>\ndbus-x11-debuginfo-1.12.8-18.el8_6.2.ppc64le.rpm<\/p>\n<p dir=\"ltr\">s390x:<br \/>\ndbus-daemon-debuginfo-1.12.8-18.el8_6.2.s390x.rpm<br \/>\ndbus-debuginfo-1.12.8-18.el8_6.2.s390x.rpm<br \/>\ndbus-debugsource-1.12.8-18.el8_6.2.s390x.rpm<br \/>\ndbus-devel-1.12.8-18.el8_6.2.s390x.rpm<br \/>\ndbus-libs-debuginfo-1.12.8-18.el8_6.2.s390x.rpm<br \/>\ndbus-tests-debuginfo-1.12.8-18.el8_6.2.s390x.rpm<br \/>\ndbus-tools-debuginfo-1.12.8-18.el8_6.2.s390x.rpm<br \/>\ndbus-x11-1.12.8-18.el8_6.2.s390x.rpm<br \/>\ndbus-x11-debuginfo-1.12.8-18.el8_6.2.s390x.rpm<\/p>\n<p dir=\"ltr\">x86_64:<br \/>\ndbus-daemon-debuginfo-1.12.8-18.el8_6.2.i686.rpm<br \/>\ndbus-daemon-debuginfo-1.12.8-18.el8_6.2.x86_64.rpm<br \/>\ndbus-debuginfo-1.12.8-18.el8_6.2.i686.rpm<br \/>\ndbus-debuginfo-1.12.8-18.el8_6.2.x86_64.rpm<br \/>\ndbus-debugsource-1.12.8-18.el8_6.2.i686.rpm<br \/>\ndbus-debugsource-1.12.8-18.el8_6.2.x86_64.rpm<br \/>\ndbus-devel-1.12.8-18.el8_6.2.i686.rpm<br \/>\ndbus-devel-1.12.8-18.el8_6.2.x86_64.rpm<br \/>\ndbus-libs-debuginfo-1.12.8-18.el8_6.2.i686.rpm<br \/>\ndbus-libs-debuginfo-1.12.8-18.el8_6.2.x86_64.rpm<br \/>\ndbus-tests-debuginfo-1.12.8-18.el8_6.2.i686.rpm<br \/>\ndbus-tests-debuginfo-1.12.8-18.el8_6.2.x86_64.rpm<br \/>\ndbus-tools-debuginfo-1.12.8-18.el8_6.2.i686.rpm<br \/>\ndbus-tools-debuginfo-1.12.8-18.el8_6.2.x86_64.rpm<br \/>\ndbus-x11-1.12.8-18.el8_6.2.x86_64.rpm<br \/>\ndbus-x11-debuginfo-1.12.8-18.el8_6.2.i686.rpm<br \/>\ndbus-x11-debuginfo-1.12.8-18.el8_6.2.x86_64.rpm<\/p>\n<p dir=\"ltr\">Red Hat Enterprise Linux BaseOS EUS (v.8.6):<\/p>\n<p dir=\"ltr\">Source:<br \/>\ndbus-1.12.8-18.el8_6.2.src.rpm<\/p>\n<p dir=\"ltr\">aarch64:<br \/>\ndbus-1.12.8-18.el8_6.2.aarch64.rpm<br \/>\ndbus-daemon-1.12.8-18.el8_6.2.aarch64.rpm<br \/>\ndbus-daemon-debuginfo-1.12.8-18.el8_6.2.aarch64.rpm<br \/>\ndbus-debuginfo-1.12.8-18.el8_6.2.aarch64.rpm<br \/>\ndbus-debugsource-1.12.8-18.el8_6.2.aarch64.rpm<br \/>\ndbus-libs-1.12.8-18.el8_6.2.aarch64.rpm<br \/>\ndbus-libs-debuginfo-1.12.8-18.el8_6.2.aarch64.rpm<br \/>\ndbus-tests-debuginfo-1.12.8-18.el8_6.2.aarch64.rpm<br \/>\ndbus-tools-1.12.8-18.el8_6.2.aarch64.rpm<br \/>\ndbus-tools-debuginfo-1.12.8-18.el8_6.2.aarch64.rpm<br \/>\ndbus-x11-debuginfo-1.12.8-18.el8_6.2.aarch64.rpm<\/p>\n<p dir=\"ltr\">noarch:<br \/>\ndbus-common-1.12.8-18.el8_6.2.noarch.rpm<\/p>\n<p dir=\"ltr\">ppc64le:<br \/>\ndbus-1.12.8-18.el8_6.2.ppc64le.rpm<br \/>\ndbus-daemon-1.12.8-18.el8_6.2.ppc64le.rpm<br \/>\ndbus-daemon-debuginfo-1.12.8-18.el8_6.2.ppc64le.rpm<br \/>\ndbus-debuginfo-1.12.8-18.el8_6.2.ppc64le.rpm<br \/>\ndbus-debugsource-1.12.8-18.el8_6.2.ppc64le.rpm<br \/>\ndbus-libs-1.12.8-18.el8_6.2.ppc64le.rpm<br \/>\ndbus-libs-debuginfo-1.12.8-18.el8_6.2.ppc64le.rpm<br \/>\ndbus-tests-debuginfo-1.12.8-18.el8_6.2.ppc64le.rpm<br \/>\ndbus-tools-1.12.8-18.el8_6.2.ppc64le.rpm<br \/>\ndbus-tools-debuginfo-1.12.8-18.el8_6.2.ppc64le.rpm<br \/>\ndbus-x11-debuginfo-1.12.8-18.el8_6.2.ppc64le.rpm<\/p>\n<p dir=\"ltr\">s390x:<br \/>\ndbus-1.12.8-18.el8_6.2.s390x.rpm<br \/>\ndbus-daemon-1.12.8-18.el8_6.2.s390x.rpm<br \/>\ndbus-daemon-debuginfo-1.12.8-18.el8_6.2.s390x.rpm<br \/>\ndbus-debuginfo-1.12.8-18.el8_6.2.s390x.rpm<br \/>\ndbus-debugsource-1.12.8-18.el8_6.2.s390x.rpm<br \/>\ndbus-libs-1.12.8-18.el8_6.2.s390x.rpm<br \/>\ndbus-libs-debuginfo-1.12.8-18.el8_6.2.s390x.rpm<br \/>\ndbus-tests-debuginfo-1.12.8-18.el8_6.2.s390x.rpm<br \/>\ndbus-tools-1.12.8-18.el8_6.2.s390x.rpm<br \/>\ndbus-tools-debuginfo-1.12.8-18.el8_6.2.s390x.rpm<br \/>\ndbus-x11-debuginfo-1.12.8-18.el8_6.2.s390x.rpm<\/p>\n<p dir=\"ltr\">x86_64:<br \/>\ndbus-1.12.8-18.el8_6.2.x86_64.rpm<br \/>\ndbus-daemon-1.12.8-18.el8_6.2.x86_64.rpm<br \/>\ndbus-daemon-debuginfo-1.12.8-18.el8_6.2.i686.rpm<br \/>\ndbus-daemon-debuginfo-1.12.8-18.el8_6.2.x86_64.rpm<br \/>\ndbus-debuginfo-1.12.8-18.el8_6.2.i686.rpm<br \/>\ndbus-debuginfo-1.12.8-18.el8_6.2.x86_64.rpm<br \/>\ndbus-debugsource-1.12.8-18.el8_6.2.i686.rpm<br \/>\ndbus-debugsource-1.12.8-18.el8_6.2.x86_64.rpm<br \/>\ndbus-libs-1.12.8-18.el8_6.2.i686.rpm<br \/>\ndbus-libs-1.12.8-18.el8_6.2.x86_64.rpm<br \/>\ndbus-libs-debuginfo-1.12.8-18.el8_6.2.i686.rpm<br \/>\ndbus-libs-debuginfo-1.12.8-18.el8_6.2.x86_64.rpm<br \/>\ndbus-tests-debuginfo-1.12.8-18.el8_6.2.i686.rpm<br \/>\ndbus-tests-debuginfo-1.12.8-18.el8_6.2.x86_64.rpm<br \/>\ndbus-tools-1.12.8-18.el8_6.2.x86_64.rpm<br \/>\ndbus-tools-debuginfo-1.12.8-18.el8_6.2.i686.rpm<br \/>\ndbus-tools-debuginfo-1.12.8-18.el8_6.2.x86_64.rpm<br \/>\ndbus-x11-debuginfo-1.12.8-18.el8_6.2.i686.rpm<br \/>\ndbus-x11-debuginfo-1.12.8-18.el8_6.2.x86_64.rpm<\/p>\n<p dir=\"ltr\">These packages are GPG signed by Red Hat for security. Our key and<br \/>\ndetails on how to verify the signature are available from<br \/>\nhttps:\/\/access.redhat.com\/security\/team\/key\/<\/p>\n<p dir=\"ltr\">7. References:<\/p>\n<p dir=\"ltr\">https:\/\/access.redhat.com\/security\/cve\/CVE-2022-42010<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-42011<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-42012<br \/>\nhttps:\/\/access.redhat.com\/security\/updates\/classification\/#moderate<\/p>\n<p dir=\"ltr\">8. Contact:<\/p>\n<p dir=\"ltr\">The Red Hat security contact is &lt;secalert@redhat.com&gt;. More contact<br \/>\ndetails at https:\/\/access.redhat.com\/security\/team\/contact\/<\/p>\n<p dir=\"ltr\">Copyright 2022 Red Hat, Inc.<br \/>\n&#8212;&#8211;BEGIN PGP SIGNATURE&#8212;&#8211;<br \/>\nVersion: GnuPG v1<\/p>\n<p dir=\"ltr\">iQIVAwUBY487yNzjgjWX9erEAQil6BAAqKXiCludPQSXvqzPc3CL\/Yb795vEBw7R<br \/>\nqt7JrctEIoqHQcVUnIg6oCsTjBvPifgNTJcrABK\/s6vrMDj5AbDWphEX4wN9MZdm<br \/>\n1zYhHRhWU0djTRem5JLuIKlTBW1yBbBF6s0Ljt4s2kHwbBxEoryq8LJFA9kfSE1b<br \/>\nC9S9H2kUVpGvp\/BGV1+ctScRUFnPDHhLr0UlX6ZlFoX+ZYjemC22WruSZruMRaIw<br \/>\n0GX8BuyCqE7C+HyMuPRQAmnDMjg\/CEsXxbxFbToraq+7PThE6uBR2o5Oa6uRkPZI<br \/>\nVhdpAC\/zpdGsB4Nlxt1vxtcAO0dwG10iSbkf3JRwlz41mkVtHbZuPj\/zSG\/50svP<br \/>\nbttJYrg1oie\/uyaSO9p1zzXE1hEkVm\/Z4ifdYFS6kCZI5902esVB+Mdx33AN\/o0K<br \/>\napUUYgNMya1PvE8HHt+nTEz5nwLY2fqT59t2wNfUTT45fA1va6jjWRFesT\/KtrLy<br \/>\nh\/QDw6Wo8+0c4aptJHTQg7Db+Vc9jiVY3HpL7P13Y\/MsIKYnHHtdFIT8lJM6uJ7T<br \/>\n5UIVUQ5MyYQ1QzBCA3+wN7iWBE2l8tkFlKiHTDGA+HCJdJd8dQOqQ9xWSCzmV0uM<br \/>\n0KAc1QQJJXv6K8C40qalcKicuX4UHOJlgYWeCMv9MuhfjOwpEzpwwBmzJ\/76b9ZF<br \/>\nHxnLBkfYkhU=sTmH<br \/>\n&#8212;&#8211;END PGP SIGNATURE&#8212;&#8211;<br \/>\n&#8212;<br \/>\nRHSA-announce mailing list<br \/>\nRHSA-announce@redhat.com<br \/>\nhttps:\/\/listman.redhat.com\/mailman\/listinfo\/rhsa-announce<\/p>\n","protected":false},"excerpt":{"rendered":"<p>&#8212;&#8211;BEGIN PGP SIGNED MESSAGE&#8212;&#8211; Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: dbus security update Advisory ID: RHSA-2022:8812-01 Product: Red Hat Enterprise Linux Advisory URL: https:\/\/access.redhat.com\/errata\/RHSA-2022:8812 Issue date: 2022-12-06 CVE Names: CVE-2022-42010 CVE-2022-42011 CVE-2022-42012 ==================================================================== 1. Summary: An update for dbus is now available for Red Hat Enterprise Linux 8.6 Extended Update Support. Red &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-34488","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/34488","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=34488"}],"version-history":[{"count":2,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/34488\/revisions"}],"predecessor-version":[{"id":34756,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/34488\/revisions\/34756"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=34488"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=34488"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=34488"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}