Logo
componentdbus-broker
Name
dbus-broker
Version
29
Type
library
Description
dbus broker
Licenses
Apache-2.0
PURL
-
CPE
cpe:2.3:*:dbus-broker_project:dbus-broker:29:*:*:*:*:*:*:*

Other Versions#


Project
Branch
Version
master
37
scarthgap
32

Patches#


#
Title
Author
Resolve
1
strnspn: fix buffer overflow
David Rheinsberg <david.rheinsberg@gmail.com>
CVE-2022-31212

Vulnerabilities#


Name
Analysis
Description
Exploitable
An issue was discovered in dbus-broker before 31. Multiple NULL pointer dereferences can be found when supplying a malformed XML config file.
Patched
An issue was discovered in dbus-broker before 31. It depends on c-uitl/c-shquote to parse the DBus service's Exec line. c-shquote contains a stack-based buffer over-read if a malicious Exec line is supplied.