File _patchinfo of Package patchinfo.26362
<patchinfo incident="26362">
<issue tracker="cve" id="2022-42010"/>
<issue tracker="cve" id="2022-42011"/>
<issue tracker="cve" id="2022-42012"/>
<issue tracker="bnc" id="1204112">VUL-0: CVE-2022-42011: dbus-1: dbus-marshal-validate: Validate length of arrays of fixed-length items</issue>
<issue tracker="bnc" id="1204113">VUL-0: CVE-2022-42012: dbus-1: dbus-marshal-byteswap: Byte-swap Unix fd indexes if needed</issue>
<issue tracker="bnc" id="1204111">VUL-0: CVE-2022-42010: dbus-1: dbus-marshal-validate: Check brackets in signature nest correctly</issue>
<issue tracker="bnc" id="1087072">dbus-1: Disable assertions to prevent un-expected DDoS attacks</issue>
<packager>simotek</packager>
<rating>important</rating>
<category>security</category>
<reboot_needed/>
<summary>Security update for dbus-1</summary>
<description>This update for dbus-1 fixes the following issues:
- CVE-2022-42010: Fixed potential crash that could be triggered by an invalid signature (bsc#1204111).
- CVE-2022-42011: Fixed an out of bounds read caused by a fixed length array (bsc#1204112).
- CVE-2022-42012: Fixed a use-after-free that could be trigged by a message in non-native endianness with out-of-band Unix file descriptor (bsc#1204113).
Bugfixes:
- Disable asserts (bsc#1087072).
</description>
</patchinfo>