[USN-5945-1] Protocol Buffers vulnerabilities

Severity High
Affected Packages 47
CVEs 3

Several security issues were fixed in Protocol Buffers.

It was discovered that Protocol Buffers did not properly validate field
com.google.protobuf.UnknownFieldSet in protobuf-java. An attacker could
possibly use this issue to perform a denial of service attack. This issue
only affected protobuf Ubuntu 22.04 LTS and Ubuntu 22.10. (CVE-2021-22569)

It was discovered that Protocol Buffers did not properly parse certain
symbols. An attacker could possibly use this issue to cause a denial of
service or other unspecified impact. (CVE-2021-22570)

It was discovered that Protocol Buffers did not properly manage memory when
parsing specifically crafted messages. An attacker could possibly use this
issue to cause applications using protobuf to crash, resulting in a denial
of service. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS,
Ubuntu 22.04 LTS and Ubuntu 22.10. (CVE-2022-1941)

Package Affected Version
pkg:deb/ubuntu/ruby-google-protobuf?distro=kinetic < 3.12.4-1ubuntu7.22.10.1
pkg:deb/ubuntu/ruby-google-protobuf?distro=jammy < 3.12.4-1ubuntu7.22.04.1
pkg:deb/ubuntu/ruby-google-protobuf?distro=focal < 3.6.1.3-2ubuntu5.2
pkg:deb/ubuntu/python3-protobuf?distro=kinetic < 3.12.4-1ubuntu7.22.10.1
pkg:deb/ubuntu/python3-protobuf?distro=jammy < 3.12.4-1ubuntu7.22.04.1
pkg:deb/ubuntu/python3-protobuf?distro=focal < 3.6.1.3-2ubuntu5.2
pkg:deb/ubuntu/python3-protobuf?distro=bionic < 3.0.0-9.1ubuntu1.1
pkg:deb/ubuntu/python-protobuf?distro=trusty < 2.5.0-9ubuntu1+esm1
pkg:deb/ubuntu/python-protobuf?distro=focal < 3.6.1.3-2ubuntu5.2
pkg:deb/ubuntu/python-protobuf?distro=bionic < 3.0.0-9.1ubuntu1.1
pkg:deb/ubuntu/protobuf-compiler?distro=trusty < 2.5.0-9ubuntu1+esm1
pkg:deb/ubuntu/protobuf-compiler?distro=kinetic < 3.12.4-1ubuntu7.22.10.1
pkg:deb/ubuntu/protobuf-compiler?distro=jammy < 3.12.4-1ubuntu7.22.04.1
pkg:deb/ubuntu/protobuf-compiler?distro=focal < 3.6.1.3-2ubuntu5.2
pkg:deb/ubuntu/protobuf-compiler?distro=bionic < 3.0.0-9.1ubuntu1.1
pkg:deb/ubuntu/libprotoc8?distro=trusty < 2.5.0-9ubuntu1+esm1
pkg:deb/ubuntu/libprotoc23?distro=kinetic < 3.12.4-1ubuntu7.22.10.1
pkg:deb/ubuntu/libprotoc23?distro=jammy < 3.12.4-1ubuntu7.22.04.1
pkg:deb/ubuntu/libprotoc17?distro=focal < 3.6.1.3-2ubuntu5.2
pkg:deb/ubuntu/libprotoc10?distro=bionic < 3.0.0-9.1ubuntu1.1
pkg:deb/ubuntu/libprotoc-dev?distro=trusty < 2.5.0-9ubuntu1+esm1
pkg:deb/ubuntu/libprotoc-dev?distro=kinetic < 3.12.4-1ubuntu7.22.10.1
pkg:deb/ubuntu/libprotoc-dev?distro=jammy < 3.12.4-1ubuntu7.22.04.1
pkg:deb/ubuntu/libprotoc-dev?distro=focal < 3.6.1.3-2ubuntu5.2
pkg:deb/ubuntu/libprotoc-dev?distro=bionic < 3.0.0-9.1ubuntu1.1
pkg:deb/ubuntu/libprotobuf8?distro=trusty < 2.5.0-9ubuntu1+esm1
pkg:deb/ubuntu/libprotobuf23?distro=kinetic < 3.12.4-1ubuntu7.22.10.1
pkg:deb/ubuntu/libprotobuf23?distro=jammy < 3.12.4-1ubuntu7.22.04.1
pkg:deb/ubuntu/libprotobuf17?distro=focal < 3.6.1.3-2ubuntu5.2
pkg:deb/ubuntu/libprotobuf10?distro=bionic < 3.0.0-9.1ubuntu1.1
pkg:deb/ubuntu/libprotobuf-lite8?distro=trusty < 2.5.0-9ubuntu1+esm1
pkg:deb/ubuntu/libprotobuf-lite23?distro=kinetic < 3.12.4-1ubuntu7.22.10.1
pkg:deb/ubuntu/libprotobuf-lite23?distro=jammy < 3.12.4-1ubuntu7.22.04.1
pkg:deb/ubuntu/libprotobuf-lite17?distro=focal < 3.6.1.3-2ubuntu5.2
pkg:deb/ubuntu/libprotobuf-lite10?distro=bionic < 3.0.0-9.1ubuntu1.1
pkg:deb/ubuntu/libprotobuf-java?distro=trusty < 2.5.0-9ubuntu1+esm1
pkg:deb/ubuntu/libprotobuf-java?distro=kinetic < 3.12.4-1ubuntu7.22.10.1
pkg:deb/ubuntu/libprotobuf-java?distro=jammy < 3.12.4-1ubuntu7.22.04.1
pkg:deb/ubuntu/libprotobuf-java?distro=focal < 3.6.1.3-2ubuntu5.2
pkg:deb/ubuntu/libprotobuf-java?distro=bionic < 3.0.0-9.1ubuntu1.1
pkg:deb/ubuntu/libprotobuf-dev?distro=trusty < 2.5.0-9ubuntu1+esm1
pkg:deb/ubuntu/libprotobuf-dev?distro=kinetic < 3.12.4-1ubuntu7.22.10.1
pkg:deb/ubuntu/libprotobuf-dev?distro=jammy < 3.12.4-1ubuntu7.22.04.1
pkg:deb/ubuntu/libprotobuf-dev?distro=focal < 3.6.1.3-2ubuntu5.2
pkg:deb/ubuntu/libprotobuf-dev?distro=bionic < 3.0.0-9.1ubuntu1.1
pkg:deb/ubuntu/elpa-protobuf-mode?distro=kinetic < 3.12.4-1ubuntu7.22.10.1
pkg:deb/ubuntu/elpa-protobuf-mode?distro=jammy < 3.12.4-1ubuntu7.22.04.1
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:deb/ubuntu/ruby-google-protobuf?distro=kinetic ubuntu ruby-google-protobuf < 3.12.4-1ubuntu7.22.10.1 kinetic
Affected pkg:deb/ubuntu/ruby-google-protobuf?distro=jammy ubuntu ruby-google-protobuf < 3.12.4-1ubuntu7.22.04.1 jammy
Affected pkg:deb/ubuntu/ruby-google-protobuf?distro=focal ubuntu ruby-google-protobuf < 3.6.1.3-2ubuntu5.2 focal
Affected pkg:deb/ubuntu/python3-protobuf?distro=kinetic ubuntu python3-protobuf < 3.12.4-1ubuntu7.22.10.1 kinetic
Affected pkg:deb/ubuntu/python3-protobuf?distro=jammy ubuntu python3-protobuf < 3.12.4-1ubuntu7.22.04.1 jammy
Affected pkg:deb/ubuntu/python3-protobuf?distro=focal ubuntu python3-protobuf < 3.6.1.3-2ubuntu5.2 focal
Affected pkg:deb/ubuntu/python3-protobuf?distro=bionic ubuntu python3-protobuf < 3.0.0-9.1ubuntu1.1 bionic
Affected pkg:deb/ubuntu/python-protobuf?distro=trusty ubuntu python-protobuf < 2.5.0-9ubuntu1+esm1 trusty
Affected pkg:deb/ubuntu/python-protobuf?distro=focal ubuntu python-protobuf < 3.6.1.3-2ubuntu5.2 focal
Affected pkg:deb/ubuntu/python-protobuf?distro=bionic ubuntu python-protobuf < 3.0.0-9.1ubuntu1.1 bionic
Affected pkg:deb/ubuntu/protobuf-compiler?distro=trusty ubuntu protobuf-compiler < 2.5.0-9ubuntu1+esm1 trusty
Affected pkg:deb/ubuntu/protobuf-compiler?distro=kinetic ubuntu protobuf-compiler < 3.12.4-1ubuntu7.22.10.1 kinetic
Affected pkg:deb/ubuntu/protobuf-compiler?distro=jammy ubuntu protobuf-compiler < 3.12.4-1ubuntu7.22.04.1 jammy
Affected pkg:deb/ubuntu/protobuf-compiler?distro=focal ubuntu protobuf-compiler < 3.6.1.3-2ubuntu5.2 focal
Affected pkg:deb/ubuntu/protobuf-compiler?distro=bionic ubuntu protobuf-compiler < 3.0.0-9.1ubuntu1.1 bionic
Affected pkg:deb/ubuntu/libprotoc8?distro=trusty ubuntu libprotoc8 < 2.5.0-9ubuntu1+esm1 trusty
Affected pkg:deb/ubuntu/libprotoc23?distro=kinetic ubuntu libprotoc23 < 3.12.4-1ubuntu7.22.10.1 kinetic
Affected pkg:deb/ubuntu/libprotoc23?distro=jammy ubuntu libprotoc23 < 3.12.4-1ubuntu7.22.04.1 jammy
Affected pkg:deb/ubuntu/libprotoc17?distro=focal ubuntu libprotoc17 < 3.6.1.3-2ubuntu5.2 focal
Affected pkg:deb/ubuntu/libprotoc10?distro=bionic ubuntu libprotoc10 < 3.0.0-9.1ubuntu1.1 bionic
Affected pkg:deb/ubuntu/libprotoc-dev?distro=trusty ubuntu libprotoc-dev < 2.5.0-9ubuntu1+esm1 trusty
Affected pkg:deb/ubuntu/libprotoc-dev?distro=kinetic ubuntu libprotoc-dev < 3.12.4-1ubuntu7.22.10.1 kinetic
Affected pkg:deb/ubuntu/libprotoc-dev?distro=jammy ubuntu libprotoc-dev < 3.12.4-1ubuntu7.22.04.1 jammy
Affected pkg:deb/ubuntu/libprotoc-dev?distro=focal ubuntu libprotoc-dev < 3.6.1.3-2ubuntu5.2 focal
Affected pkg:deb/ubuntu/libprotoc-dev?distro=bionic ubuntu libprotoc-dev < 3.0.0-9.1ubuntu1.1 bionic
Affected pkg:deb/ubuntu/libprotobuf8?distro=trusty ubuntu libprotobuf8 < 2.5.0-9ubuntu1+esm1 trusty
Affected pkg:deb/ubuntu/libprotobuf23?distro=kinetic ubuntu libprotobuf23 < 3.12.4-1ubuntu7.22.10.1 kinetic
Affected pkg:deb/ubuntu/libprotobuf23?distro=jammy ubuntu libprotobuf23 < 3.12.4-1ubuntu7.22.04.1 jammy
Affected pkg:deb/ubuntu/libprotobuf17?distro=focal ubuntu libprotobuf17 < 3.6.1.3-2ubuntu5.2 focal
Affected pkg:deb/ubuntu/libprotobuf10?distro=bionic ubuntu libprotobuf10 < 3.0.0-9.1ubuntu1.1 bionic
Affected pkg:deb/ubuntu/libprotobuf-lite8?distro=trusty ubuntu libprotobuf-lite8 < 2.5.0-9ubuntu1+esm1 trusty
Affected pkg:deb/ubuntu/libprotobuf-lite23?distro=kinetic ubuntu libprotobuf-lite23 < 3.12.4-1ubuntu7.22.10.1 kinetic
Affected pkg:deb/ubuntu/libprotobuf-lite23?distro=jammy ubuntu libprotobuf-lite23 < 3.12.4-1ubuntu7.22.04.1 jammy
Affected pkg:deb/ubuntu/libprotobuf-lite17?distro=focal ubuntu libprotobuf-lite17 < 3.6.1.3-2ubuntu5.2 focal
Affected pkg:deb/ubuntu/libprotobuf-lite10?distro=bionic ubuntu libprotobuf-lite10 < 3.0.0-9.1ubuntu1.1 bionic
Affected pkg:deb/ubuntu/libprotobuf-java?distro=trusty ubuntu libprotobuf-java < 2.5.0-9ubuntu1+esm1 trusty
Affected pkg:deb/ubuntu/libprotobuf-java?distro=kinetic ubuntu libprotobuf-java < 3.12.4-1ubuntu7.22.10.1 kinetic
Affected pkg:deb/ubuntu/libprotobuf-java?distro=jammy ubuntu libprotobuf-java < 3.12.4-1ubuntu7.22.04.1 jammy
Affected pkg:deb/ubuntu/libprotobuf-java?distro=focal ubuntu libprotobuf-java < 3.6.1.3-2ubuntu5.2 focal
Affected pkg:deb/ubuntu/libprotobuf-java?distro=bionic ubuntu libprotobuf-java < 3.0.0-9.1ubuntu1.1 bionic
Affected pkg:deb/ubuntu/libprotobuf-dev?distro=trusty ubuntu libprotobuf-dev < 2.5.0-9ubuntu1+esm1 trusty
Affected pkg:deb/ubuntu/libprotobuf-dev?distro=kinetic ubuntu libprotobuf-dev < 3.12.4-1ubuntu7.22.10.1 kinetic
Affected pkg:deb/ubuntu/libprotobuf-dev?distro=jammy ubuntu libprotobuf-dev < 3.12.4-1ubuntu7.22.04.1 jammy
Affected pkg:deb/ubuntu/libprotobuf-dev?distro=focal ubuntu libprotobuf-dev < 3.6.1.3-2ubuntu5.2 focal
Affected pkg:deb/ubuntu/libprotobuf-dev?distro=bionic ubuntu libprotobuf-dev < 3.0.0-9.1ubuntu1.1 bionic
Affected pkg:deb/ubuntu/elpa-protobuf-mode?distro=kinetic ubuntu elpa-protobuf-mode < 3.12.4-1ubuntu7.22.10.1 kinetic
Affected pkg:deb/ubuntu/elpa-protobuf-mode?distro=jammy ubuntu elpa-protobuf-mode < 3.12.4-1ubuntu7.22.04.1 jammy
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...