Lucene search

K
mageiaGentoo FoundationMGASA-2023-0092
HistoryMar 19, 2023 - 1:16 a.m.

Updated protobuf packages fix security vulnerability

2023-03-1901:16:28
Gentoo Foundation
advisories.mageia.org
144
protobuf
parsing
vulnerability
security
denial of service
cve-2022-1941
protobuf-python
protobuf-java-core
protobuf-java-lite
crafted input
unix

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

0.003 Low

EPSS

Percentile

71.0%

Parsing vulnerability for the MessageSet type in the ProtocolBuffers for protobuf-python can lead to out of memory can lead to a Denial of Service against services receiving unsanitized input. (CVE-2022-1941) A parsing issue with binary data in protobuf-java core and lite can lead to a denial of service attack with crafted input. (CVE-2022-3171)

OSVersionArchitecturePackageVersionFilename
Mageia8noarchprotobuf< 3.14.0-1.2protobuf-3.14.0-1.2.mga8

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

0.003 Low

EPSS

Percentile

71.0%