Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:40184
HistoryApr 19, 2023 - 7:47 a.m.

Integer Overflow

2023-04-1907:47:02
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
6
libprotobuf-c.so
integer overflow
parse_required_member
denial of service

0.0004 Low

EPSS

Percentile

5.1%

libprotobuf-c.so is vulnerable to Integer Overflow. The vulnerability exists in the parse_required_member function of protobuf-c.c, because the method does not check if the len >= pref_len which will result in an integer overflow, possibly leading to Denial of Service.

References