Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-33070

Опубликовано: 23 июн. 2022
Источник: redhat
CVSS3: 3.1

Описание

Protobuf-c v1.4.0 was discovered to contain an invalid arithmetic shift via the function parse_tag_and_wiretype in protobuf-c/protobuf-c.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via unspecified vectors.

A flaw was found in protobuf-c. The issue occurs due to an invalid arithmetic shift via the parse_tag_and_wiretype in the protobuf-c/protobuf-c.c function. This flaw allows attackers to cause a denial of service (DoS) via unspecified vectors.

Отчет

The vulnerability has been marked low as exploiting this vulnerability is highly unlikely to be possible as user input isn't taken by the vulnerable functions.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7protobuf-cOut of support scope
Red Hat Enterprise Linux 8protobuf-cFix deferred
Red Hat Enterprise Linux 9protobuf-cFix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=2102598protobuf-c: invalid arithmetic shift via the function parse_tag_and_wiretype may lead to DoS

3.1 Low

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 3 лет назад

Protobuf-c v1.4.0 was discovered to contain an invalid arithmetic shift via the function parse_tag_and_wiretype in protobuf-c/protobuf-c.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via unspecified vectors.

CVSS3: 5.5
nvd
около 3 лет назад

Protobuf-c v1.4.0 was discovered to contain an invalid arithmetic shift via the function parse_tag_and_wiretype in protobuf-c/protobuf-c.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via unspecified vectors.

CVSS3: 5.5
debian
около 3 лет назад

Protobuf-c v1.4.0 was discovered to contain an invalid arithmetic shif ...

CVSS3: 5.5
github
около 3 лет назад

Protobuf-c v1.4.0 was discovered to contain an invalid arithmetic shift via the function parse_tag_and_wiretype in protobuf-c/protobuf-c.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via unspecified vectors.

CVSS3: 6.5
fstec
около 3 лет назад

Уязвимость функции parse_tag_and_wiretype компонента protobuf-c.c протокола сериализации данных на языке программирования C Protobuf-c, позволяющая нарушителю вызвать отказ в обслуживании

3.1 Low

CVSS3