CVE-2024-2410
Public on 2024-05-03
Modified on 2024-05-09
Description
The JsonToBinaryStream() function is part of the protocol buffers C++ implementation and is used to parse JSON from a stream. If the input is broken up into separate chunks in a certain way, the parser will attempt to read bytes from a chunk that has already been freed.
Severity
CVSS v3 Base Score
See breakdown
Affected Packages
Platform | Package | Release Date | Advisory | Status |
---|---|---|---|---|
Amazon Linux 1 | compat-protobuf | Not Affected | ||
Amazon Linux 2023 | grpc | Not Affected | ||
Amazon Linux 1 | protobuf | Not Affected | ||
Amazon Linux 2 - Core | protobuf | Not Affected | ||
Amazon Linux 2023 | protobuf | Not Affected | ||
Amazon Linux 2 - Core | protobuf-c | Not Affected | ||
Amazon Linux 2023 | protobuf-c | Not Affected |
CVSS Scores
Score Type | Score | Vector | |
---|---|---|---|
Amazon Linux | CVSSv3 | 7.6 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L |
NVD | CVSSv3 | 7.6 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L |