CVE-2022-3509
Summary
| CVE | CVE-2022-3509 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-12-12 13:15:00 UTC |
| Updated | 2022-12-15 16:57:00 UTC |
| Description | A parsing issue similar to CVE-2022-3171, but with textformat in protobuf-java core and lite versions prior to 3.21.7, 3.20.3, 3.19.6 and 3.16.3 can lead to a denial of service attack. Inputs containing multiple instances of non-repeated embedded messages with repeated or unknown fields causes objects to be converted back-n-forth between mutable and immutable forms, resulting in potentially long garbage collection pauses. We recommend updating to the versions mentioned above. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Protobuf-java | All | All | All | All | |
| Application | Protobuf-javalite | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Clean up TextFormat parser (#10673) · protocolbuffers/protobuf@a3888f5 · GitHub | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 182017 Debian Security Update for protobuf (CVE-2022-3509)
- 20391 IBM DB2 Denial of Service (DoS) Vulnerability (7087234)
- 378733 IBM WebSphere Application Server Liberty Denial of Service (DoS) Vulnerability (6841889)
- 378776 IBM MQ Deniel of Service (DoS) Vulnerabilities (6960535)
- 378883 Splunk Enterprise August Third Party Package Updates (SVD-2023-0808)
- 378990 Atlassian Jira Service Management Data Center and Server Denial of Service (DoS) Vulnerability (JSDSERVER-14749,JSDSERVER-14751,JSDSERVER-14752,JSDSERVER-14753,JSDSERVER-14754,JSDSERVER-14755)
- 710705 Gentoo Linux protobuf-java Denial of Service (DoS) Vulnerability (GLSA 202301-09)
- 731312 Atlassian Jira Software Data Center and Server Denial of Service (DoS) Vulnerability (JSWSERVER-25790)