Input validation error in protobuf-c - CVE-2022-33070
Published: July 28, 2022 / Updated: April 25, 2023
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input within the parse_tag_and_wiretype() function in protobuf-c/protobuf-c.c. A remote attacker can trick the victim to open a specially crafted file, cause an invalid arithmetic shift and perform a denial of service (DoS) attack.
Affected software
cflinuxfs3
Amazon Linux AMI
Gentoo Linux
Ubuntu
openEuler
Fedora
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Isolation Segment
VMware Tanzu Application Service for VMs
protobuf-c-compiler (Ubuntu package)
protobuf-c-devel
protobuf-c-debugsource
protobuf-c-debuginfo
protobuf-c
dev-libs/protobuf-c
sudo (Ubuntu package)
sudo-ldap (Ubuntu package)
sudo-help
sudo-devel
sudo-debugsource
sudo-debuginfo
sudo
VMware Tanzu Operations Manager
How to mitigate CVE-2022-33070
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 5.3
cflinuxfs3 - update to 0.351.0
protobuf-c-compiler (Ubuntu package) - addressed in versions 1.3.3-1ubuntu0.1, 1.3.3-1ubuntu2.1
protobuf-c-devel - update to 1.4.0-2
protobuf-c-debugsource - update to 1.4.0-2
protobuf-c-debuginfo - update to 1.4.0-2
protobuf-c - update to 1.4.0-2
dev-libs/protobuf-c - update to 1.4.1
protobuf-c - update to 1.4.1-2
protobuf-c - update to 1.4.1-2.fc36
sudo (Ubuntu package) - addressed in versions 1.8.21p2-3ubuntu1.5, 1.8.31-1ubuntu1.4, 1.9.9-1ubuntu2.2, 1.9.11p3-1ubuntu1.1
sudo-ldap (Ubuntu package) - addressed in versions 1.8.21p2-3ubuntu1.5, 1.8.31-1ubuntu1.4, 1.9.9-1ubuntu2.2, 1.9.11p3-1ubuntu1.1
sudo-help - update to 1.9.2-6
sudo-devel - update to 1.9.2-6
sudo-debugsource - update to 1.9.2-6
sudo-debuginfo - update to 1.9.2-6
sudo - update to 1.9.2-6
Isolation Segment - addressed in versions 2.11.29, 2.12.19, 2.13.14, 3.0.7
VMware Tanzu Application Service for VMs - addressed in versions 2.11.35, 2.12.24, 2.13.17, 3.0.7
VMware Tanzu Operations Manager - update to 3.0.4
External References
Related Security Bulletins
- Denial of service in Protobuf-c
- Ubuntu update for protobuf-c
- Ubuntu update for sudo
- Multiple vulnerabilities in Cloud Foundry Foundation cflinuxfs3
- VMware Tanzu products update for Sudo
- openEuler 22.03 LTS update for protobuf-c
- openEuler update for sudo
- Amazon Linux AMI update for protobuf-c
- Gentoo update for protobuf-c
- Fedora 36 update for protobuf-c
- Multiple vulnerabilities in IBM Watson Speech Services Cartridge