Lucene search

K
ubuntucveUbuntu.comUB:CVE-2022-33070
HistoryJun 23, 2022 - 12:00 a.m.

CVE-2022-33070

2022-06-2300:00:00
ubuntu.com
ubuntu.com
22
protobuf-c v1.4.0
invalid arithmetic shift
denial of service
unspecified vectors
ubuntu
sudo
patched

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

42.3%

Protobuf-c v1.4.0 was discovered to contain an invalid arithmetic shift via
the function parse_tag_and_wiretype in protobuf-c/protobuf-c.c. This
vulnerability allows attackers to cause a Denial of Service (DoS) via
unspecified vectors.

Bugs

Notes

Author Note
mdeslaur pidgin in precise+ uses embedded libgadu
alexmurray The various Ubuntu source packages listed against this CVE all contain an embedded copy of protobuf-c but they still needed to be triaged to determine if they actually use their own embedded copy or whether they link against the system libprotobuf-c
mdeslaur in sudo, only used by sudo_logsrvd, setting priority to low
eslerm sudo is patched and they sent PR to protobuf-c upstream

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

42.3%