Advisories ยป MGASA-2023-0092

Updated protobuf packages fix security vulnerability

Publication date: 18 Mar 2023
Modification date: 18 Mar 2023
Type: security
Affected Mageia releases : 8
CVE: CVE-2022-1941 , CVE-2022-3171

Description

Parsing vulnerability for the MessageSet type in the ProtocolBuffers for
protobuf-python can lead to out of memory can lead to a Denial of Service
against services receiving unsanitized input. (CVE-2022-1941)
A parsing issue with binary data in protobuf-java core and lite can lead
to a denial of service attack with crafted input. (CVE-2022-3171)
                

References

SRPMS

8/core