HIGH
KDiskMark before 3.1.0 lacks authorization checking for D-Bus methods such as Helper::flushPageCache
Published Sep 14, 2022
7.8
HIGHCVSS 3.1
EPSS 0.37%
Description
KDiskMark before 3.1.0 lacks authorization checking for D-Bus methods such as Helper::flushPageCache.
Affected products
No data.
Configuration 1
- < 3.1.0
Configuration 2
- 36
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (5)
- http://www.openwall.com/lists/oss-security/2022/09/14/1 mailing-listx_refsource_MLISTExploitIssue TrackingMailing ListThird Party Advisory
- https://github.com/JonMagon/KDiskMark/commit/3c90083a4f5ba3f240a797e509d818221542bbdc x_refsource_MISCPatchThird Party Advisory
- https://github.com/JonMagon/KDiskMark/compare/3.0.0...3.1.0 x_refsource_MISCRelease NotesThird Party Advisory
- https://github.com/JonMagon/KDiskMark/releases/tag/3.1.0 x_refsource_MISCRelease NotesThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YYO3GWTNPHNCLHSI562Q3KX43PW7FQ4Q/ vendor-advisoryx_refsource_FEDORA
| Link | Providers | Tags |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2022/09/14/1 | mailing-listx_refsource_MLISTExploitIssue TrackingMailing ListThird Party Advisory | |
| https://github.com/JonMagon/KDiskMark/commit/3c90083a4f5ba3f240a797e509d818221542bbdc | x_refsource_MISCPatchThird Party Advisory | |
| https://github.com/JonMagon/KDiskMark/compare/3.0.0...3.1.0 | x_refsource_MISCRelease NotesThird Party Advisory | |
| https://github.com/JonMagon/KDiskMark/releases/tag/3.1.0 | x_refsource_MISCRelease NotesThird Party Advisory | |
| https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YYO3GWTNPHNCLHSI562Q3KX43PW7FQ4Q/ | vendor-advisoryx_refsource_FEDORA |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Sep 14, 2022
Updated Aug 3, 2024
Reserved Sep 14, 2022
Link CVE-2022-40673
CISA Vulnrichment
Updated n/a