CVE-2022-3171
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD
Description
A parsing issue with binary data in protobuf-java core and lite versions prior to 3.21.7, 3.20.3, 3.19.6 and 3.16.3 can lead to a denial of service attack. Inputs containing multiple instances of non-repeated embedded messages with repeated or unknown fields causes objects to be converted back-n-forth between mutable and immutable forms, resulting in potentially long garbage collection pauses. We recommend updating to the versions mentioned above.
Affected (21)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.16.3 | |
| Before 3.16.3 | |
| Before 3.16.3 | |
| Before 3.16.3 | |
| Before 3.16.3 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 37 |
References (8)
Source: cve-coordination@google.com
Third Party Advisory
Source: cve-coordination@google.com
Source: cve-coordination@google.com
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Timeline
No history available yet.