dbus-1.12.20-7.el9

エラータID: AXSA:2023-4874:04

Release date: 
Friday, January 27, 2023 - 13:20
Subject: 
dbus-1.12.20-7.el9
Affected Channels: 
MIRACLE LINUX 9 for x86_64
Severity: 
Moderate
Description: 

D-Bus is a system for sending messages between applications. It is used both for the system-wide message bus service, and as a per-user-login-session messaging facility.

Security Fix(es):

* dbus: dbus-daemon crashes when receiving message with incorrectly nested parentheses and curly brackets (CVE-2022-42010)
* dbus: dbus-daemon can be crashed by messages with array length inconsistent with element type (CVE-2022-42011)
* dbus: `_dbus_marshal_byteswap` doesn't process fds in messages with "foreign" endianness correctly (CVE-2022-42012)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2022-42010
An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authenticated attacker can cause dbus-daemon and other programs that use libdbus to crash when receiving a message with certain invalid type signatures.
CVE-2022-42011
An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authenticated attacker can cause dbus-daemon and other programs that use libdbus to crash when receiving a message where an array length is inconsistent with the size of the element type.
CVE-2022-42012
An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authenticated attacker can cause dbus-daemon and other programs that use libdbus to crash by sending a message with attached file descriptors in an unexpected format.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. dbus-1.12.20-7.el9.src.rpm
    MD5: e5a6ae9511a6db7faa1b0cc4af7e3977
    SHA-256: 1c80bfe1f3dda3222d1dab4607756bdc53b0eb4df1edd20fcd64479522381a50
    Size: 2.04 MB

Asianux Server 9 for x86_64
  1. dbus-1.12.20-7.el9.x86_64.rpm
    MD5: 79fc38805db707a4cd52f524356e0f88
    SHA-256: c280915edeaac2f6582e9c382d7bc0e0bce427ffa9d38d3e79e3b9b3f7477867
    Size: 6.97 kB
  2. dbus-common-1.12.20-7.el9.noarch.rpm
    MD5: 5f39d3ecf2475db740b372bbb9307020
    SHA-256: 7c5fc9fb1a1b3984192737753a886e89f26e1dc5cf593a3de09c7241a19febd9
    Size: 13.75 kB
  3. dbus-daemon-1.12.20-7.el9.x86_64.rpm
    MD5: 66b0c88b1367067fb3aef47ffbe03098
    SHA-256: 662ee8418de0235fc7bf05537dff9c1ecd38ce6e941d9cd33833b7eb8e1130b9
    Size: 196.58 kB
  4. dbus-devel-1.12.20-7.el9.x86_64.rpm
    MD5: 21e6a84247879d3e1bc95a1659ff9477
    SHA-256: c597bd1495ab9f223dea7b01604582f6bcc1f8a5920e8551fb681e9efbe2771a
    Size: 33.11 kB
  5. dbus-libs-1.12.20-7.el9.x86_64.rpm
    MD5: 2d7196345783ca783acb138e56297f44
    SHA-256: b11138b8f29487747fb28084c53a3d169c0f540532341650bc05662e8eeb8344
    Size: 151.00 kB
  6. dbus-tools-1.12.20-7.el9.x86_64.rpm
    MD5: 972d48cd77bcc8ab05f5d340911fccd1
    SHA-256: 2f7dcf3cbed489fd5a4e5827b33a2441472178027d4ca02dd62c96f4b5e746c1
    Size: 50.58 kB
  7. dbus-x11-1.12.20-7.el9.x86_64.rpm
    MD5: d21582b4592083625b5a511ac3a3ba0a
    SHA-256: ba0c15ac9a6397da59a663689889825c276f534a1303f145816a4fba52774849
    Size: 23.78 kB
  8. dbus-devel-1.12.20-7.el9.i686.rpm
    MD5: 365ea337270c1e0dbb4c86d9841696e6
    SHA-256: 75812d4da42a51cc641205d8d4f81d65a880c9893734d15460f4f49e9dec5c08
    Size: 33.12 kB
  9. dbus-libs-1.12.20-7.el9.i686.rpm
    MD5: dced72104a9a9859a0bff2c796a51fb2
    SHA-256: 6f1ef490899288ba094a6671bf0a16d7d89bde76f3db8b34eb6ccabd741e4f7f
    Size: 164.03 kB