Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

T. Longin

Researcher fromSEC Consult Vulnerability Lab
#17919of 53,633
15Total CVSS
Vulnerabilities · 2
High
2
PT-2022-20611
7.5
2022-06-25
Unknown · C-Uitl/C-Shquote · CVE-2022-31212
**Name of the Vulnerable Software and Affected Versions** dbus-broker versions prior to 31 **Description** An issue was discovered in dbus-broker where it depends on c-uitl/c-shquote to parse the DBus service's Exec line. c-shquote contains a stack-based buffer over-read if a malicious Exec line is supplied. **Recommendations** For versions prior to 31, update to version 31 or later to resolve the issue. As a temporary workaround, consider restricting the use of the Exec line in the DBus service configuration to minimize the risk of exploitation.
PT-2022-20612
7.5
2022-06-25
Unknown · Dbus-Broker · CVE-2022-31213
**Name of the Vulnerable Software and Affected Versions** dbus-broker versions prior to 31 **Description** An issue was discovered in dbus-broker where multiple NULL pointer dereferences can occur when a malformed XML config file is supplied. **Recommendations** For versions prior to 31, update to version 31 or later to resolve the issue.