CVE-2022-48468

Published: 04/13/2023 21:15:07
protobuf-c before 1.4.1 has an unsigned integer overflow in parse_required_member.
MEDIUM
CVSS v3: 5.5

Status

DocFilters Release Package State Justification Comment
25.1 protobuf-c (1.3.3) Resolved Code Not Present Patched applied from https://github.com/protobuf-c/protobuf-c/commit/289f5c18b195aa43d46a619d1188709abbfa9c82
24.4 protobuf-c (1.3.3) Resolved Code Not Present Patched applied from https://github.com/protobuf-c/protobuf-c/commit/289f5c18b195aa43d46a619d1188709abbfa9c82
24.4.0 protobuf-c (1.3.3) Resolved Code Not Present Patched applied from https://github.com/protobuf-c/protobuf-c/commit/289f5c18b195aa43d46a619d1188709abbfa9c82
24.3 protobuf-c (1.3.3) Resolved Code Not Present Patched applied from https://github.com/protobuf-c/protobuf-c/commit/289f5c18b195aa43d46a619d1188709abbfa9c82
24.2.1 protobuf-c (1.3.3) Resolved Code Not Present Patched applied from https://github.com/protobuf-c/protobuf-c/commit/289f5c18b195aa43d46a619d1188709abbfa9c82
24.2 protobuf-c (1.3.3) Resolved Code Not Present Patched applied from https://github.com/protobuf-c/protobuf-c/commit/289f5c18b195aa43d46a619d1188709abbfa9c82
24.1 protobuf-c (1.3.3) Resolved Code Not Present Patched applied from https://github.com/protobuf-c/protobuf-c/commit/289f5c18b195aa43d46a619d1188709abbfa9c82
23.3 protobuf-c (1.3.3) Resolved Code Not Present Patched applied from https://github.com/protobuf-c/protobuf-c/commit/289f5c18b195aa43d46a619d1188709abbfa9c82
23.2.1 protobuf-c (1.3.3) Resolved Code Not Present Patched applied from https://github.com/protobuf-c/protobuf-c/commit/289f5c18b195aa43d46a619d1188709abbfa9c82
23.2 protobuf-c (1.3.3) Resolved Code Not Present Patched applied from https://github.com/protobuf-c/protobuf-c/commit/289f5c18b195aa43d46a619d1188709abbfa9c82
23.1 protobuf-c (1.3.3) Needs Triage
22.4 protobuf-c (1.3.3) Needs Triage
22.3 protobuf-c (1.3.3) Needs Triage
22.2 protobuf-c (1.3.3) Needs Triage
22.1 protobuf-c (1.3.3) Needs Triage

Severity score breakdown

Attack Complexity
LOW
Attack Vector
LOCAL
Availability Impact
HIGH
Base Score
5.5
Base Severity
MEDIUM
Confidentiality Impact
NONE
Integrity Impact
NONE
Privileges Required
LOW
Scope
UNCHANGED
User Interaction
NONE
Vector String
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Version
3.1

References