Vulnerability Name: | CVE-2022-40673 (CCN-236123) | ||||||||||||
Assigned: | 2022-09-14 | ||||||||||||
Published: | 2022-09-14 | ||||||||||||
Updated: | 2022-10-01 | ||||||||||||
Summary: | KDiskMark before 3.1.0 lacks authorization checking for D-Bus methods such as Helper::flushPageCache. | ||||||||||||
CVSS v3 Severity: | 7.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) 6.8 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
7.3 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 7.2 High (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C)
| ||||||||||||
Vulnerability Type: | CWE-862 | ||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2022-40673 Source: MLIST Type: Exploit, Issue Tracking, Mailing List, Third Party Advisory [oss-security] 20220914 insufficiently protected D-Bus interface in KDiskMark 3.0.0 (CVE-2022-40673) Source: XF Type: UNKNOWN kdiskmark-cve202240673-code-exec(236123) Source: CCN Type: KDiskMark GIT Repository Add missing authorization checking in Helper::flushPageCache() Source: MISC Type: Patch, Third Party Advisory https://github.com/JonMagon/KDiskMark/commit/3c90083a4f5ba3f240a797e509d818221542bbdc Source: MISC Type: Release Notes, Third Party Advisory https://github.com/JonMagon/KDiskMark/compare/3.0.0...3.1.0 Source: MISC Type: Release Notes, Third Party Advisory https://github.com/JonMagon/KDiskMark/releases/tag/3.1.0 Source: FEDORA Type: Mailing List, Third Party Advisory FEDORA-2022-97149edce1 Source: CCN Type: oss-sec Mailing List, Wed, 14 Sep 2022 11:56:48 +0200 insufficiently protected D-Bus interface in KDiskMark 3.0.0 (CVE-2022-40673) | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Denotes that component is vulnerable | ||||||||||||
BACK |