CVE-2022-48468

Name
CVE-2022-48468
Description
protobuf-c before 1.4.1 has an unsigned integer overflow in parse_required_member.
NVD Severity
high
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
MISC https://github.com/protobuf-c/protobuf-c/issues/499
MISC https://github.com/protobuf-c/protobuf-c/pull/513
MISC https://github.com/protobuf-c/protobuf-c/commit/ec3d900001a13ccdaa8aef996b34c61159c76217
MISC https://github.com/protobuf-c/protobuf-c/releases/tag/v1.4.1

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:protobuf-c_project:protobuf-c:*:*:*:*:*:*:*:* protobuf-c >= None < 1.4.1

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
protobuf-c 3.15-main 1.4.0-r0 Leonardo Arena <rnalrd@alpinelinux.org> possibly vulnerable
protobuf-c 3.14-main 1.3.3-r6 Leonardo Arena <rnalrd@alpinelinux.org> possibly vulnerable