#VU65855 Input validation error in protobuf-c - CVE-2022-33070
Published: July 28, 2022 / Updated: April 25, 2023
protobuf-c
protobuf-c
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input within the parse_tag_and_wiretype() function in protobuf-c/protobuf-c.c. A remote attacker can trick the victim to open a specially crafted file, cause an invalid arithmetic shift and perform a denial of service (DoS) attack.