[prev in list] [next in list] [prev in thread] [next in thread] 

List:       oss-security
Subject:    [oss-security] CVE-2022-1941: Protobuf C++, Python DoS
From:       Ana Oprea <anaoprea () google ! com>
Date:       2022-09-27 15:33:16
Message-ID: CABbtqzEUXKVaWAK49231jQCPYF9_A2kGfDUz-LY_d7LtBJnsbA () mail ! gmail ! com
[Download RAW message or body]


Summary
A message parsing and memory management vulnerability in ProtocolBuffer=E2=
=80=99s
C++ and Python implementations can trigger an out of memory (OOM) failure
when processing a specially crafted message, which could lead to a denial
of service (DoS) on services using the libraries.

Reporter
ClusterFuzz [1]

Affected versions
All versions of C++ Protobufs (including Python) prior to the versions
listed below.

Severity & Impact
CVE-2022-1941 Medium 5.7 - CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H [2]
A small (~500 KB) malicious payload can be constructed which causes the
running service to allocate more than 3GB of RAM.

Proof of Concept
For reproduction details, please refer to the unit test that identifies the
specific inputs that exercise this parsing weakness. [3]

Mitigation / Patching
Please update to the latest available versions of the following packages:
- protobuf-cpp (3.18.3, 3.19.5, 3.20.2, 3.21.6)
- protobuf-python (3.18.3, 3.19.5, 3.20.2, 4.21.6)

[1] https://google.github.io/clusterfuzz/
[2] https://nvd.nist.gov/vuln/detail/CVE-2022-1941
[3]
https://github.com/protocolbuffers/protobuf/security/advisories/GHSA-8gq9-2=
x98-w8hf

Kind regards,
Ana


[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic