Input validation error in protobuf-c - CVE-2022-33070

 

Input validation error in protobuf-c - CVE-2022-33070

Published: July 28, 2022 / Updated: April 25, 2023


Vulnerability identifier: #VU65855
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-33070
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient validation of user-supplied input within the parse_tag_and_wiretype() function in protobuf-c/protobuf-c.c. A remote attacker can trick the victim to open a specially crafted file, cause an invalid arithmetic shift and perform a denial of service (DoS) attack.


Affected software

protobuf-c
cflinuxfs3
Amazon Linux AMI
Gentoo Linux
Ubuntu
openEuler
Fedora
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Isolation Segment
VMware Tanzu Application Service for VMs
protobuf-c-compiler (Ubuntu package)
protobuf-c-devel
protobuf-c-debugsource
protobuf-c-debuginfo
protobuf-c
dev-libs/protobuf-c
sudo (Ubuntu package)
sudo-ldap (Ubuntu package)
sudo-help
sudo-devel
sudo-debugsource
sudo-debuginfo
sudo
VMware Tanzu Operations Manager

How to mitigate CVE-2022-33070

Install updates from vendor's website.

protobuf-c - update to 1.4.1
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 5.3
cflinuxfs3 - update to 0.351.0
protobuf-c-compiler (Ubuntu package) - addressed in versions 1.3.3-1ubuntu0.1, 1.3.3-1ubuntu2.1
protobuf-c-devel - update to 1.4.0-2
protobuf-c-debugsource - update to 1.4.0-2
protobuf-c-debuginfo - update to 1.4.0-2
protobuf-c - update to 1.4.0-2
dev-libs/protobuf-c - update to 1.4.1
protobuf-c - update to 1.4.1-2
protobuf-c - update to 1.4.1-2.fc36
sudo (Ubuntu package) - addressed in versions 1.8.21p2-3ubuntu1.5, 1.8.31-1ubuntu1.4, 1.9.9-1ubuntu2.2, 1.9.11p3-1ubuntu1.1
sudo-ldap (Ubuntu package) - addressed in versions 1.8.21p2-3ubuntu1.5, 1.8.31-1ubuntu1.4, 1.9.9-1ubuntu2.2, 1.9.11p3-1ubuntu1.1
sudo-help - update to 1.9.2-6
sudo-devel - update to 1.9.2-6
sudo-debugsource - update to 1.9.2-6
sudo-debuginfo - update to 1.9.2-6
sudo - update to 1.9.2-6
Isolation Segment - addressed in versions 2.11.29, 2.12.19, 2.13.14, 3.0.7
VMware Tanzu Application Service for VMs - addressed in versions 2.11.35, 2.12.24, 2.13.17, 3.0.7
VMware Tanzu Operations Manager - update to 3.0.4

External References

Related Security Bulletins