USN-5531-1
Dashboard / Vulnerabilities / USN-5531-1
USN-5531-1
Summary: protobuf-c vulnerability
Details: Pietro Borrello discovered that protobuf-c contained an invalid arithmetic shift. This vulnerability allowed attackers to cause a denial of service (system crash) via unspecified vectors (CVE-2022-33070). It was discovered that protobuf-c contained an unsigned integer overflow. This vulnerability allowed attackers to cause a denial of service (system crash) via unspecified vectors. Todd Miller discovered that protobuf-c contained a possible NULL dereference. This could cause a vulnerability that allowed attackers to cause a denial of service (system crash) via unspecified vectors.
References: https://ubuntu.com/security/notices/USN-5531-1, https://ubuntu.com/security/CVE-2022-33070
Affected packages
Package
Name: protobuf-c
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=focal
Affected ranges
Type: ECOSYSTEM
Events:
