CVE-2022-3171
Summary
| CVE | CVE-2022-3171 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-10-12 23:15:00 UTC |
| Updated | 2023-11-07 03:50:00 UTC |
| Description | A parsing issue with binary data in protobuf-java core and lite versions prior to 3.21.7, 3.20.3, 3.19.6 and 3.16.3 can lead to a denial of service attack. Inputs containing multiple instances of non-repeated embedded messages with repeated or unknown fields causes objects to be converted back-n-forth between mutable and immutable forms, resulting in potentially long garbage collection pauses. We recommend updating to the versions mentioned above. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Fedoraproject | Fedora | 37 | All | All | All |
| Application | Google-protobuf | All | All | All | All | |
| Application | Protobuf-java | All | All | All | All | |
| Application | Protobuf-javalite | All | All | All | All | |
| Application | Protobuf-kotlin | All | All | All | All | |
| Application | Protobuf-kotlin-lite | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [SECURITY] Fedora 37 Update: protobuf-3.19.6-1.fc37 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| A potential Denial of Service issue in protobuf-java · Advisory · protocolbuffers/protobuf · GitHub | CONFIRM | github.com | |
| [SECURITY] Fedora 36 Update: perl-Alien-ProtoBuf-0.09-17.fc36 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| protobuf-java: Denial of Service (GLSA 202301-09) — Gentoo security | GENTOO | security.gentoo.org | |
| [SECURITY] Fedora 37 Update: protobuf-3.19.6-1.fc37 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| [SECURITY] Fedora 36 Update: perl-Alien-ProtoBuf-0.09-17.fc36 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 20317 Oracle Database 21c Critical Patch Update - January 2023
- 20318 Oracle Database 19c Critical Patch Update - January 2023
- 20319 Oracle Database 19c Critical OJVM Patch Update - January 2023
- 20391 IBM DB2 Denial of Service (DoS) Vulnerability (7087234)
- 283528 Fedora Security Update for protobuf (FEDORA-2022-25f35ed634)
- 284287 Fedora Security Update for perl (FEDORA-2022-15729fa33d)
- 355269 Amazon Linux Security Advisory for protobuf : ALAS2023-2023-049
- 377910 Oracle MySQL Connectors 8.0.x Denial of Service (DoS) Vulnerability (CPUJAN2023)
- 378553 IBM MQ Blockchain bridge Denial of Service (DoS) Vulnerability within protobuf-java core (6853381)
- 378733 IBM WebSphere Application Server Liberty Denial of Service (DoS) Vulnerability (6841889)
- 378776 IBM MQ Deniel of Service (DoS) Vulnerabilities (6960535)
- 378883 Splunk Enterprise August Third Party Package Updates (SVD-2023-0808)
- 378990 Atlassian Jira Service Management Data Center and Server Denial of Service (DoS) Vulnerability (JSDSERVER-14749,JSDSERVER-14751,JSDSERVER-14752,JSDSERVER-14753,JSDSERVER-14754,JSDSERVER-14755)
- 691034 Free Berkeley Software Distribution (FreeBSD) Security Update for mysql (dc49f6dc-99d2-11ed-86e9-d4c9ef517024)
- 710705 Gentoo Linux protobuf-java Denial of Service (DoS) Vulnerability (GLSA 202301-09)
- 731313 Atlassian Jira Software Data Center and Server Denial of Service (DoS) Vulnerability (JSWSERVER-25789)
- 752777 SUSE Enterprise Linux Security Update for protobuf (SUSE-SU-2022:3922-1)
- 754157 SUSE Enterprise Linux Security Update for grpc, protobuf, python-Deprecated, python-PyGithub, python-aiocontextvars, python-avro, python-bcrypt, python-cryptography, python-cryptography-vectors, python-google-api-core, pyt (SUSE-SU-2023:2783-1)
- 754878 SUSE Enterprise Linux Security Update for grpc, protobuf, python-DEPRECATED, python-PyGithub, python-aiocontextvars, python-avro, python-bcrypt, python-cryptography, python-cryptography-vectors, python-google-api-core, pyt (SUSE-SU-2023:2783-2)