Skip to content

libdbus CVE-2022-42010

Moderate
etungsten published GHSA-2jrr-88f8-fqq6 Nov 17, 2022

Package

libdbus (bottlerocket)

Affected versions

< 1.11.0

Patched versions

1.11.0

Description

An authenticated attacker could cause dbus-daemon and other programs that use libdbus to crash when receiving a message with specific invalid type signatures.

Severity

Moderate

CVE ID

CVE-2022-42010

Weaknesses

No CWEs