Описание
Nullptr dereference when a null char is present in a proto symbol. The symbol is parsed incorrectly, leading to an unchecked call into the proto file's name during generation of the resulting error message. Since the symbol is incorrectly parsed, the file is nullptr. We recommend upgrading to version 3.15.0 or greater.
A flaw was found in protobuf. The vulnerability occurs due to incorrect parsing of a NULL character in the proto symbol and leads to a Null pointer dereference. This flaw allows an attacker to execute unauthorized code or commands, read memory, modify memory.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 7 | protobuf | Out of support scope | ||
Red Hat OpenShift Container Platform 4 | openshift4/ose-kuryr-cni-rhel8 | Will not fix | ||
Red Hat OpenShift Container Platform 4 | openshift4/ose-kuryr-controller-rhel8 | Will not fix | ||
Red Hat Quay 3 | quay/quay-rhel8 | Not affected | ||
Red Hat Enterprise Linux 8 | protobuf | Fixed | RHSA-2022:7464 | 08.11.2022 |
Red Hat Enterprise Linux 8.6 Extended Update Support | protobuf | Fixed | RHSA-2024:3433 | 28.05.2024 |
Red Hat Enterprise Linux 9 | protobuf | Fixed | RHSA-2022:7970 | 15.11.2022 |
Red Hat OpenStack Platform 16.1 | protobuf | Fixed | RHSA-2022:8860 | 07.12.2022 |
Red Hat OpenStack Platform 16.2 | protobuf | Fixed | RHSA-2022:8847 | 07.12.2022 |
Показывать по
Дополнительная информация
Статус:
EPSS
7.5 High
CVSS3
Связанные уязвимости
Nullptr dereference when a null char is present in a proto symbol. The symbol is parsed incorrectly, leading to an unchecked call into the proto file's name during generation of the resulting error message. Since the symbol is incorrectly parsed, the file is nullptr. We recommend upgrading to version 3.15.0 or greater.
Nullptr dereference when a null char is present in a proto symbol. The symbol is parsed incorrectly, leading to an unchecked call into the proto file's name during generation of the resulting error message. Since the symbol is incorrectly parsed, the file is nullptr. We recommend upgrading to version 3.15.0 or greater.
Nullptr dereference when a null char is present in a proto symbol. The ...
EPSS
7.5 High
CVSS3