CVE-2022-42011

Source
https://cve.org/CVERecord?id=CVE-2022-42011
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-42011.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2022-42011
Downstream
Related
Published
2022-10-10T00:15:09.573Z
Modified
2026-04-16T00:07:07.646842764Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authenticated attacker can cause dbus-daemon and other programs that use libdbus to crash when receiving a message where an array length is inconsistent with the size of the element type.

Database specific
{
    "unresolved_ranges": [
        {
            "cpe": "cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*",
            "source": "CPE_FIELD",
            "extracted_events": [
                {
                    "last_affected": "35"
                }
            ]
        },
        {
            "cpe": "cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*",
            "source": "CPE_FIELD",
            "extracted_events": [
                {
                    "last_affected": "36"
                }
            ]
        },
        {
            "cpe": "cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*",
            "source": "CPE_FIELD",
            "extracted_events": [
                {
                    "last_affected": "37"
                }
            ]
        }
    ]
}
References

Affected packages

Git / gitlab.freedesktop.org/dbus/dbus

Affected ranges

Type
GIT
Repo
https://gitlab.freedesktop.org/dbus/dbus
Events
Database specific
{
    "cpe": "cpe:2.3:a:freedesktop:dbus:*:*:*:*:*:*:*:*",
    "source": "CPE_FIELD",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "1.12.24"
        },
        {
            "introduced": "1.13.0"
        },
        {
            "fixed": "1.14.4"
        },
        {
            "introduced": "1.15.0"
        },
        {
            "fixed": "1.15.2"
        }
    ]
}

Affected versions

dbus-0.*
dbus-0.1
dbus-0.10
dbus-0.11
dbus-0.12
dbus-0.13
dbus-0.2
dbus-0.20
dbus-0.21
dbus-0.22
dbus-0.23
dbus-0.3
dbus-0.31.0
dbus-0.32.0
dbus-0.33.0
dbus-0.34.0
dbus-0.35
dbus-0.36
dbus-0.4
dbus-0.5
dbus-0.50
dbus-0.6
dbus-0.60
dbus-0.61
dbus-0.62
dbus-0.7
dbus-0.8
dbus-0.9
dbus-0.90
dbus-0.91
dbus-0.92
dbus-0.93
dbus-0.94
dbus-0.95
dbus-1.*
dbus-1.0.0
dbus-1.1.0
dbus-1.1.2
dbus-1.1.20
dbus-1.1.3
dbus-1.1.4
dbus-1.10.0
dbus-1.11.0
dbus-1.11.10
dbus-1.11.12
dbus-1.11.14
dbus-1.11.16
dbus-1.11.18
dbus-1.11.2
dbus-1.11.20
dbus-1.11.22
dbus-1.11.4
dbus-1.11.6
dbus-1.11.8
dbus-1.12.0
dbus-1.12.10
dbus-1.12.12
dbus-1.12.14
dbus-1.12.16
dbus-1.12.18
dbus-1.12.2
dbus-1.12.20
dbus-1.12.22
dbus-1.12.4
dbus-1.12.6
dbus-1.12.8
dbus-1.13.0
dbus-1.13.10
dbus-1.13.12
dbus-1.13.14
dbus-1.13.16
dbus-1.13.18
dbus-1.13.2
dbus-1.13.20
dbus-1.13.22
dbus-1.13.4
dbus-1.13.6
dbus-1.13.8
dbus-1.14.0
dbus-1.14.2
dbus-1.15.0
dbus-1.2.1
dbus-1.3.0
dbus-1.3.1
dbus-1.4.0
dbus-1.4.1
dbus-1.4.4
dbus-1.4.6
dbus-1.5.0
dbus-1.5.10
dbus-1.5.12
dbus-1.5.2
dbus-1.5.4
dbus-1.5.6
dbus-1.5.8
dbus-1.6.0
dbus-1.7.0
dbus-1.7.10
dbus-1.7.2
dbus-1.7.4
dbus-1.7.6
dbus-1.7.8
dbus-1.8.0
dbus-1.9.0
dbus-1.9.10
dbus-1.9.12
dbus-1.9.14
dbus-1.9.16
dbus-1.9.18
dbus-1.9.2
dbus-1.9.20
dbus-1.9.4
dbus-1.9.8
Other
dbus-before-object-names-merge
dbus-object-names-branchpoint

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-42011.json"