CVE-2021-22570

Public on 2022-01-26
Modified on 2024-02-12
Description
Nullptr dereference when a null char is present in a proto symbol. The symbol is parsed incorrectly, leading to an unchecked call into the proto file's name during generation of the resulting error message. Since the symbol is incorrectly parsed, the file is nullptr. We recommend upgrading to version 3.15.0 or greater.
Severity
Medium severity
Medium
CVSS v3 Base Score
7.5
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 1 protobuf 2023-01-31 ALAS-2023-1676 Fixed
Amazon Linux 2 - Core protobuf 2023-02-17 ALAS2-2023-1948 Fixed
Amazon Linux 2023 protobuf 2023-02-17 ALAS2023-2023-009 Fixed

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
NVD CVSSv3 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
NVD CVSSv2 2.1 AV:L/AC:L/Au:N/C:N/I:N/A:P