CVE-2022-33070: Medium severity red hat protobuf-c vulnerability
Published Jun 22, 2022
·Updated
Protobuf-c v1.4.0 was discovered to contain an invalid arithmetic shift via the function parsetagandwiretype in protobuf-c/protobuf-c.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via unspecified vectors.
Affected Software
2 affected components
Protobuf-c Project Protobuf-c=1.4.0
Fedoraproject Fedora=36
Remediation
Patch Available
Patch Available
Event History
Jun 22, 2022
CVE Published
via MITRE·01:24 PM
Data Sourced
via MITRE·01:24 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of Protobuf-c v1.4.0?
The vulnerability ID is CVE-2022-33070.
2
What is the severity of CVE-2022-33070?
The severity of CVE-2022-33070 is rated as medium with a CVSS score of 5.5.
3
How can attackers exploit CVE-2022-33070?
Attackers can exploit this vulnerability to cause a Denial of Service (DoS) via unspecified vectors.
4
In which function of Protobuf-c v1.4.0 was the invalid arithmetic shift discovered?
The invalid arithmetic shift was discovered in the function parse_tag_and_wiretype in protobuf-c/protobuf-c.c.
5
What software versions are affected by CVE-2022-33070?
Versions 1.4.0 of Protobuf-c and Fedora 36 are affected by this vulnerability.