File _patchinfo of Package patchinfo.26361

<patchinfo incident="26361">
  <issue tracker="cve" id="2022-42011"/>
  <issue tracker="cve" id="2022-42012"/>
  <issue tracker="cve" id="2022-42010"/>
  <issue tracker="bnc" id="1204112">VUL-0: CVE-2022-42011: dbus-1: dbus-marshal-validate: Validate length of arrays of fixed-length items</issue>
  <issue tracker="bnc" id="1204113">VUL-0: CVE-2022-42012: dbus-1: dbus-marshal-byteswap: Byte-swap Unix fd indexes if needed</issue>
  <issue tracker="bnc" id="1204111">VUL-0: CVE-2022-42010: dbus-1: dbus-marshal-validate: Check brackets in signature nest correctly</issue>
  <issue tracker="bnc" id="1087072">dbus-1: Disable assertions to prevent un-expected DDoS attacks</issue>
  <packager>simotek</packager>
  <rating>important</rating>
  <category>security</category>
  <reboot_needed/>
  <summary>Security update for dbus-1</summary>
  <description>This update for dbus-1 fixes the following issues:

  - CVE-2022-42010: Fixed potential crash that could be triggered by an invalid signature (bsc#1204111).
  - CVE-2022-42011: Fixed an out of bounds read caused by a fixed length array (bsc#1204112).
  - CVE-2022-42012: Fixed a use-after-free that could be trigged by a message in non-native endianness with out-of-band Unix file descriptor (bsc#1204113).

  Bugfixes:

  - Disable asserts (bsc#1087072).

</description>
</patchinfo>
openSUSE Build Service is sponsored by