Bug 1200332 - (CVE-2022-31212) VUL-0: CVE-2022-31212: dbus-broker: a stack buffer over-read if a malicious Exec line is supplied
(CVE-2022-31212)
VUL-0: CVE-2022-31212: dbus-broker: a stack buffer over-read if a malicious E...
Status: NEW
Classification: openSUSE
Product: openSUSE Distribution
Classification: openSUSE
Component: Security
Leap 15.3
Other Other
: P3 - Medium : Normal (vote)
: ---
Assigned To: Security Team bot
Security Team bot
https://smash.suse.de/issue/333893/
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2022-06-08 13:01 UTC by Thomas Leroy
Modified: 2022-06-25 19:16 UTC (History)
0 users

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Thomas Leroy 2022-06-08 13:01:49 UTC
rh#2094718

Dbus-Broker depends on c-uitl/c-shquote to parse DBus service's Exec line. c-shquote contains a stack buffer over-read if a malicious Exec line is supplied.

References:
https://bugzilla.redhat.com/show_bug.cgi?id=2094718
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-31212
Comment 1 Thomas Leroy 2022-06-08 13:29:33 UTC
The shquote upstream bug fix should be [0], included in the c-shquote v1, shipped from v30 in dbus-broker.

Therefore we only have affected:
- openSUSE:Backports:SLE-15-SP3
- openSUSE:Backports:SLE-15-SP4

[0] https://github.com/c-util/c-shquote/commit/7fd15f8e272136955f7ffc37df29fbca9ddceca1
Comment 2 Simon Lees 2022-06-09 00:58:24 UTC
(In reply to Thomas Leroy from comment #1)
> The shquote upstream bug fix should be [0], included in the c-shquote v1,
> shipped from v30 in dbus-broker.
> 
> Therefore we only have affected:
> - openSUSE:Backports:SLE-15-SP3

This version has dbus-broker 11, which from inspection of the sources didn't yet bundle "c-shquote" so it seems this version is fine.
Comment 3 Simon Lees 2022-06-09 01:21:02 UTC
(In reply to Thomas Leroy from comment #1)
> The shquote upstream bug fix should be [0], included in the c-shquote v1,
> shipped from v30 in dbus-broker.
> 
> Therefore we only have affected:
> - openSUSE:Backports:SLE-15-SP4

mr#981404
Comment 4 Simon Lees 2022-06-09 01:21:35 UTC
Submission Created reassigning to security
Comment 5 OBSbugzilla Bot 2022-06-22 14:40:06 UTC
This is an autogenerated message for OBS integration:
This bug (1200332) was mentioned in
https://build.opensuse.org/request/show/984474 Backports:SLE-15-SP4 / dbus-broker
Comment 6 Swamp Workflow Management 2022-06-25 19:16:03 UTC
openSUSE-SU-2022:10030-1: An update that fixes two vulnerabilities is now available.

Category: security (moderate)
Bug References: 1200332,1200333
CVE References: CVE-2022-31212,CVE-2022-31213
JIRA References: 
Sources used:
openSUSE Backports SLE-15-SP4 (src):    dbus-broker-28-bp154.2.3.1