VDB
BDU%3A2023-03849
BDU%3A2023-03849
PUBLISHED
CVSS 7.800000190734863 HIGH
Уязвимость функции parse_tag_and_wiretype компонента protobuf-c.c протокола сериализации данных на языке программирования C Protobuf-c, позволяющая нарушителю вызвать отказ в обслуживании
Risk Scores
CVSS 2.0
7.800000190734863
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Сообщество свободного программного обеспечения, ООО «РусБИТех-Астра», Google Inc | Debian GNU/Linux, Astra Linux Special Edition (запись в едином реестре российских программ №369), protobuf-c |
Timeline
- Jul 20, 2023 CVE Published
- Sep 20, 2023 CVE Updated
References
- https://github.com/protobuf-c/protobuf-c/commit/6e389ce2c34355d36009a8fb1666bed29fa2d4f4 url
- https://github.com/protobuf-c/protobuf-c/pull/508 url
- https://nvd.nist.gov/vuln/detail/CVE-2022-33070 url
- https://security-tracker.debian.org/tracker/CVE-2022-33070 url
- https://wiki.astralinux.ru/astra-linux-se17-bulletin-2023-0630SE17MD url
- https://wiki.astralinux.ru/astra-linux-se47-bulletin-2023-0907SE47 url
- https://github.com/protobuf-c/protobuf-c/issues/506 advisory