[ALAS-2023-1676] Amazon Linux AMI 2014.03 - ALAS-2023-1676: medium priority package update for protobuf

Severity Medium
Affected Packages 22
CVEs 1

Package updates are available for Amazon Linux AMI that fix the following vulnerabilities:
CVE-2021-22570:
A flaw was found in protobuf. The vulnerability occurs due to incorrect parsing of a NULL character in the proto symbol and leads to a Null pointer dereference. This flaw allows an attacker to execute unauthorized code or commands, read memory, modify memory.

Package Affected Version
pkg:rpm/amazonlinux/protobuf?arch=x86_64&distro=amazonlinux-1 < 2.5.0-1.11.amzn1
pkg:rpm/amazonlinux/protobuf?arch=i686&distro=amazonlinux-1 < 2.5.0-1.11.amzn1
pkg:rpm/amazonlinux/protobuf-vim?arch=x86_64&distro=amazonlinux-1 < 2.5.0-1.11.amzn1
pkg:rpm/amazonlinux/protobuf-vim?arch=i686&distro=amazonlinux-1 < 2.5.0-1.11.amzn1
pkg:rpm/amazonlinux/protobuf-static?arch=x86_64&distro=amazonlinux-1 < 2.5.0-1.11.amzn1
pkg:rpm/amazonlinux/protobuf-static?arch=i686&distro=amazonlinux-1 < 2.5.0-1.11.amzn1
pkg:rpm/amazonlinux/protobuf-python27?arch=x86_64&distro=amazonlinux-1 < 2.5.0-1.11.amzn1
pkg:rpm/amazonlinux/protobuf-python27?arch=i686&distro=amazonlinux-1 < 2.5.0-1.11.amzn1
pkg:rpm/amazonlinux/protobuf-python26?arch=x86_64&distro=amazonlinux-1 < 2.5.0-1.11.amzn1
pkg:rpm/amazonlinux/protobuf-python26?arch=i686&distro=amazonlinux-1 < 2.5.0-1.11.amzn1
pkg:rpm/amazonlinux/protobuf-lite?arch=x86_64&distro=amazonlinux-1 < 2.5.0-1.11.amzn1
pkg:rpm/amazonlinux/protobuf-lite?arch=i686&distro=amazonlinux-1 < 2.5.0-1.11.amzn1
pkg:rpm/amazonlinux/protobuf-lite-static?arch=x86_64&distro=amazonlinux-1 < 2.5.0-1.11.amzn1
pkg:rpm/amazonlinux/protobuf-lite-static?arch=i686&distro=amazonlinux-1 < 2.5.0-1.11.amzn1
pkg:rpm/amazonlinux/protobuf-lite-devel?arch=x86_64&distro=amazonlinux-1 < 2.5.0-1.11.amzn1
pkg:rpm/amazonlinux/protobuf-lite-devel?arch=i686&distro=amazonlinux-1 < 2.5.0-1.11.amzn1
pkg:rpm/amazonlinux/protobuf-devel?arch=x86_64&distro=amazonlinux-1 < 2.5.0-1.11.amzn1
pkg:rpm/amazonlinux/protobuf-devel?arch=i686&distro=amazonlinux-1 < 2.5.0-1.11.amzn1
pkg:rpm/amazonlinux/protobuf-debuginfo?arch=x86_64&distro=amazonlinux-1 < 2.5.0-1.11.amzn1
pkg:rpm/amazonlinux/protobuf-debuginfo?arch=i686&distro=amazonlinux-1 < 2.5.0-1.11.amzn1
pkg:rpm/amazonlinux/protobuf-compiler?arch=x86_64&distro=amazonlinux-1 < 2.5.0-1.11.amzn1
pkg:rpm/amazonlinux/protobuf-compiler?arch=i686&distro=amazonlinux-1 < 2.5.0-1.11.amzn1
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/amazonlinux/protobuf?arch=x86_64&distro=amazonlinux-1 amazonlinux protobuf < 2.5.0-1.11.amzn1 amazonlinux-1 x86_64
Affected pkg:rpm/amazonlinux/protobuf?arch=i686&distro=amazonlinux-1 amazonlinux protobuf < 2.5.0-1.11.amzn1 amazonlinux-1 i686
Affected pkg:rpm/amazonlinux/protobuf-vim?arch=x86_64&distro=amazonlinux-1 amazonlinux protobuf-vim < 2.5.0-1.11.amzn1 amazonlinux-1 x86_64
Affected pkg:rpm/amazonlinux/protobuf-vim?arch=i686&distro=amazonlinux-1 amazonlinux protobuf-vim < 2.5.0-1.11.amzn1 amazonlinux-1 i686
Affected pkg:rpm/amazonlinux/protobuf-static?arch=x86_64&distro=amazonlinux-1 amazonlinux protobuf-static < 2.5.0-1.11.amzn1 amazonlinux-1 x86_64
Affected pkg:rpm/amazonlinux/protobuf-static?arch=i686&distro=amazonlinux-1 amazonlinux protobuf-static < 2.5.0-1.11.amzn1 amazonlinux-1 i686
Affected pkg:rpm/amazonlinux/protobuf-python27?arch=x86_64&distro=amazonlinux-1 amazonlinux protobuf-python27 < 2.5.0-1.11.amzn1 amazonlinux-1 x86_64
Affected pkg:rpm/amazonlinux/protobuf-python27?arch=i686&distro=amazonlinux-1 amazonlinux protobuf-python27 < 2.5.0-1.11.amzn1 amazonlinux-1 i686
Affected pkg:rpm/amazonlinux/protobuf-python26?arch=x86_64&distro=amazonlinux-1 amazonlinux protobuf-python26 < 2.5.0-1.11.amzn1 amazonlinux-1 x86_64
Affected pkg:rpm/amazonlinux/protobuf-python26?arch=i686&distro=amazonlinux-1 amazonlinux protobuf-python26 < 2.5.0-1.11.amzn1 amazonlinux-1 i686
Affected pkg:rpm/amazonlinux/protobuf-lite?arch=x86_64&distro=amazonlinux-1 amazonlinux protobuf-lite < 2.5.0-1.11.amzn1 amazonlinux-1 x86_64
Affected pkg:rpm/amazonlinux/protobuf-lite?arch=i686&distro=amazonlinux-1 amazonlinux protobuf-lite < 2.5.0-1.11.amzn1 amazonlinux-1 i686
Affected pkg:rpm/amazonlinux/protobuf-lite-static?arch=x86_64&distro=amazonlinux-1 amazonlinux protobuf-lite-static < 2.5.0-1.11.amzn1 amazonlinux-1 x86_64
Affected pkg:rpm/amazonlinux/protobuf-lite-static?arch=i686&distro=amazonlinux-1 amazonlinux protobuf-lite-static < 2.5.0-1.11.amzn1 amazonlinux-1 i686
Affected pkg:rpm/amazonlinux/protobuf-lite-devel?arch=x86_64&distro=amazonlinux-1 amazonlinux protobuf-lite-devel < 2.5.0-1.11.amzn1 amazonlinux-1 x86_64
Affected pkg:rpm/amazonlinux/protobuf-lite-devel?arch=i686&distro=amazonlinux-1 amazonlinux protobuf-lite-devel < 2.5.0-1.11.amzn1 amazonlinux-1 i686
Affected pkg:rpm/amazonlinux/protobuf-devel?arch=x86_64&distro=amazonlinux-1 amazonlinux protobuf-devel < 2.5.0-1.11.amzn1 amazonlinux-1 x86_64
Affected pkg:rpm/amazonlinux/protobuf-devel?arch=i686&distro=amazonlinux-1 amazonlinux protobuf-devel < 2.5.0-1.11.amzn1 amazonlinux-1 i686
Affected pkg:rpm/amazonlinux/protobuf-debuginfo?arch=x86_64&distro=amazonlinux-1 amazonlinux protobuf-debuginfo < 2.5.0-1.11.amzn1 amazonlinux-1 x86_64
Affected pkg:rpm/amazonlinux/protobuf-debuginfo?arch=i686&distro=amazonlinux-1 amazonlinux protobuf-debuginfo < 2.5.0-1.11.amzn1 amazonlinux-1 i686
Affected pkg:rpm/amazonlinux/protobuf-compiler?arch=x86_64&distro=amazonlinux-1 amazonlinux protobuf-compiler < 2.5.0-1.11.amzn1 amazonlinux-1 x86_64
Affected pkg:rpm/amazonlinux/protobuf-compiler?arch=i686&distro=amazonlinux-1 amazonlinux protobuf-compiler < 2.5.0-1.11.amzn1 amazonlinux-1 i686
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...