Bugzilla – Bug 1200332
VUL-0: CVE-2022-31212: dbus-broker: a stack buffer over-read if a malicious Exec line is supplied
Last modified: 2022-06-25 19:16:03 UTC
rh#2094718 Dbus-Broker depends on c-uitl/c-shquote to parse DBus service's Exec line. c-shquote contains a stack buffer over-read if a malicious Exec line is supplied. References: https://bugzilla.redhat.com/show_bug.cgi?id=2094718 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-31212
The shquote upstream bug fix should be [0], included in the c-shquote v1, shipped from v30 in dbus-broker. Therefore we only have affected: - openSUSE:Backports:SLE-15-SP3 - openSUSE:Backports:SLE-15-SP4 [0] https://github.com/c-util/c-shquote/commit/7fd15f8e272136955f7ffc37df29fbca9ddceca1
(In reply to Thomas Leroy from comment #1) > The shquote upstream bug fix should be [0], included in the c-shquote v1, > shipped from v30 in dbus-broker. > > Therefore we only have affected: > - openSUSE:Backports:SLE-15-SP3 This version has dbus-broker 11, which from inspection of the sources didn't yet bundle "c-shquote" so it seems this version is fine.
(In reply to Thomas Leroy from comment #1) > The shquote upstream bug fix should be [0], included in the c-shquote v1, > shipped from v30 in dbus-broker. > > Therefore we only have affected: > - openSUSE:Backports:SLE-15-SP4 mr#981404
Submission Created reassigning to security
This is an autogenerated message for OBS integration: This bug (1200332) was mentioned in https://build.opensuse.org/request/show/984474 Backports:SLE-15-SP4 / dbus-broker
openSUSE-SU-2022:10030-1: An update that fixes two vulnerabilities is now available. Category: security (moderate) Bug References: 1200332,1200333 CVE References: CVE-2022-31212,CVE-2022-31213 JIRA References: Sources used: openSUSE Backports SLE-15-SP4 (src): dbus-broker-28-bp154.2.3.1