Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: GSA_kwCzR0hTQS03N3JtLTl4OWgteGozZ80mxQ
NULL Pointer Dereference in Protocol Buffers
Nullptr dereference when a null char is present in a proto symbol. The symbol is parsed incorrectly, leading to an unchecked call into the proto file's name during generation of the resulting error message. Since the symbol is incorrectly parsed, the file is nullptr. We recommend upgrading to version 3.15.0 or greater.
Permalink: https://github.com/advisories/GHSA-77rm-9x9h-xj3gJSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS03N3JtLTl4OWgteGozZ80mxQ
Source: GitHub Advisory Database
Origin: Unspecified
Severity: High
Classification: General
Published: over 1 year ago
Updated: about 2 months ago
CVSS Score: 7.5
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Identifiers: GHSA-77rm-9x9h-xj3g, CVE-2021-22570
References:
- https://nvd.nist.gov/vuln/detail/CVE-2021-22570
- https://github.com/protocolbuffers/protobuf/releases/tag/v3.15.0
- https://lists.fedoraproject.org/archives/list/[email protected]/message/IFX6KPNOFHYD6L4XES5PCM3QNSKZBOTQ/
- https://lists.fedoraproject.org/archives/list/[email protected]/message/3DVUZPALAQ34TQP6KFNLM4IZS6B32XSA/
- https://lists.fedoraproject.org/archives/list/[email protected]/message/BTRGBRC5KGCA4SK5MUNLPYJRAGXMBIYY/
- https://lists.fedoraproject.org/archives/list/[email protected]/message/NVTWVQRB5OCCTMKEQFY5MYED3DXDVSLP/
- https://lists.fedoraproject.org/archives/list/[email protected]/message/5PAGL5M2KGYPN3VEQCRJJE6NA7D5YG5X/
- https://lists.fedoraproject.org/archives/list/[email protected]/message/KQJB6ZPRLKV6WCMX2PRRRQBFAOXFBK6B/
- https://lists.fedoraproject.org/archives/list/[email protected]/message/MRWRAXAFR3JR7XCFWTHC2KALSZKWACCE/
- https://www.oracle.com/security-alerts/cpuapr2022.html
- https://security.netapp.com/advisory/ntap-20220429-0005/
- https://lists.debian.org/debian-lts-announce/2023/04/msg00019.html
- https://github.com/advisories/GHSA-77rm-9x9h-xj3g
Affected Packages
pypi:protobuf
Versions: < 3.15.0Fixed in: 3.15.0
go:github.com/protocolbuffers/protobuf
Versions: < 3.15.0Fixed in: 3.15.0
maven:com.google.protobuf:protobuf-parent
Versions: < 3.15.0Fixed in: 3.15.0
packagist:google/protobuf
Versions: < 3.15.0Fixed in: 3.15.0
nuget:Google.Protobuf
Versions: < 3.15.0Fixed in: 3.15.0