Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-24535
HistoryJun 08, 2023 - 12:00 a.m.

CVE-2023-24535

2023-06-0800:00:00
ubuntu.com
ubuntu.com
13
parsing vulnerability
invalid messages
panic
text-format
number
whitespace

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

34.1%

Parsing invalid messages can panic. Parsing a text-format message which
contains a potential number consisting of a minus sign, one or more
characters of whitespace, and no further input will cause a panic.

Notes

Author Note
alexmurray google-guest-agent contains a vendored copy of golang-goprotobuf
mdeslaur Introduced by: https://go-review.googlesource.com/c/protobuf/+/473015 Fixed by: https://github.com/protocolbuffers/protobuf-go/commit/edaf511a7a37a90db2727b600d699e1e8d2840b4

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

34.1%