First published: Thu Apr 13 2023(Updated: )
protobuf-c before 1.4.1 has an unsigned integer overflow in parse_required_member.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM QRadar Security Information and Event Manager | <=7.5 - 7.5.0 UP9 IF03 | |
IBM Security QRadar Incident Forensics | <=7.5 - 7.5.0 UP9 IF03 | |
Red Hat Protobuf-c | <1.4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-48468 is classified as having a moderate severity due to the potential for an unsigned integer overflow.
To fix CVE-2022-48468, upgrade to protobuf-c version 1.4.1 or later.
CVE-2022-48468 affects protobuf-c versions prior to 1.4.1 as well as specific versions of IBM QRadar SIEM and IBM QRadar Incident Forensics.
CVE-2022-48468 is an unsigned integer overflow vulnerability.
CVE-2022-48468 may be exploitable remotely, depending on how the vulnerable software is integrated and deployed.