CVE-2022-33070
published 2022-06-23CVE-2022-33070: Protobuf-c v1.4.0 was discovered to contain an invalid arithmetic shift via the function parse_tag_and_wiretype in protobuf-c/protobuf-c.c. This vulnerability…
PriorityP416medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
1.06%
61.0th percentile
Protobuf-c v1.4.0 was discovered to contain an invalid arithmetic shift via the function parse_tag_and_wiretype in protobuf-c/protobuf-c.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via unspecified vectors.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | protobuf-c | < protobuf-c 1.4.1-1 (bookworm) | protobuf-c 1.4.1-1 (bookworm) |
| fedoraproject | fedora | — | — |
| msrc | cbl2_protobuf-c_1.4.0-2_on_cbl_mariner_2.0 | — | — |
| protobuf-c_project | protobuf-c | — | — |
| protobuf-c_project | protobuf-c | >= 0 < 1.4.1-1 | 1.4.1-1 |
| protobuf-c_project | protobuf-c | >= 0 < 1.4.1-1 | 1.4.1-1 |
| protobuf-c_project | protobuf-c | >= 0 < 1.4.1-1 | 1.4.1-1 |
| protobuf-c_project | protobuf-c | >= 0 < 1.3.3-1ubuntu0.1 | 1.3.3-1ubuntu0.1 |
| protobuf-c_project | protobuf-c | >= 0 < 1.3.3-1ubuntu2.1 | 1.3.3-1ubuntu2.1 |
| sudo_project | sudo | >= 0 < 1.8.21p2-3ubuntu1.5 | 1.8.21p2-3ubuntu1.5 |
| sudo_project | sudo | >= 0 < 1.8.31-1ubuntu1.4 | 1.8.31-1ubuntu1.4 |
| sudo_project | sudo | >= 0 < 1.9.9-1ubuntu2.2 | 1.9.9-1ubuntu2.2 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
sudo vulnerabilities
osv·2023-01-18·CVSS 5.5
CVE-2023-22809 [MEDIUM] sudo vulnerabilities
sudo vulnerabilities
Matthieu Barjole and Victor Cutillas discovered that Sudo incorrectly
handled user-specified editors when using the sudoedit command. A local
attacker that has permission to use the sudoedit command could possibly use
this issue to edit arbitrary files. (CVE-2023-22809)
It was discovered that the Protobuf-c library, used by Sudo, incorrectly
handled certain arithmetic shifts. An attacker could possibly use this
issue to cause Sudo to crash, resulting in a denial of service. This issue
only affected Ubuntu 22.04 LTS. (CVE-2022-33070)
OSV
protobuf-c vulnerability
osv·2022-07-26·CVSS 5.5
CVE-2022-33070 [MEDIUM] protobuf-c vulnerability
protobuf-c vulnerability
Pietro Borrello discovered that protobuf-c contained an invalid
arithmetic shift. This vulnerability allowed attackers to cause a
denial of service (system crash) via unspecified vectors
(CVE-2022-33070).
It was discovered that protobuf-c contained an unsigned integer
overflow. This vulnerability allowed attackers to cause a denial of
service (system crash) via unspecified vectors.
Todd Miller discovered that protobuf-c contained a possible NULL
dereference. This could cause a vulnerability that allowed attackers to
cause a denial of service (system crash) via unspecified vectors.
GHSA
GHSA-xcrq-6j7j-784j: Protobuf-c v1
ghsa_unreviewed·2022-06-24
CVE-2022-33070 [MEDIUM] GHSA-xcrq-6j7j-784j: Protobuf-c v1
Protobuf-c v1.4.0 was discovered to contain an invalid arithmetic shift via the function parse_tag_and_wiretype in protobuf-c/protobuf-c.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via unspecified vectors.
OSV
CVE-2022-33070: Protobuf-c v1
osv·2022-06-23·CVSS 5.5
CVE-2022-33070 [MEDIUM] CVE-2022-33070: Protobuf-c v1
Protobuf-c v1.4.0 was discovered to contain an invalid arithmetic shift via the function parse_tag_and_wiretype in protobuf-c/protobuf-c.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via unspecified vectors.
Ubuntu
Sudo vulnerabilities
vendor_ubuntu·2023-01-18·CVSS 5.5
CVE-2023-22809 [MEDIUM] Sudo vulnerabilities
Title: Sudo vulnerabilities
Summary: Several security issues were fixed in Sudo.
Matthieu Barjole and Victor Cutillas discovered that Sudo incorrectly
handled user-specified editors when using the sudoedit command. A local
attacker that has permission to use the sudoedit command could possibly use
this issue to edit arbitrary files. (CVE-2023-22809)
It was discovered that the Protobuf-c library, used by Sudo, incorrectly
handled certain arithmetic shifts. An attacker could possibly use this
issue to cause Sudo to crash, resulting in a denial of service. This issue
only affected Ubuntu 22.04 LTS. (CVE-2022-33070)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
protobuf-c vulnerability
vendor_ubuntu·2022-07-26·CVSS 5.5
CVE-2022-33070 [MEDIUM] protobuf-c vulnerability
Title: protobuf-c vulnerability
Summary: Several security issues were fixed in protobuf-c.
Pietro Borrello discovered that protobuf-c contained an invalid
arithmetic shift. This vulnerability allowed attackers to cause a
denial of service (system crash) via unspecified vectors
(CVE-2022-33070).
It was discovered that protobuf-c contained an unsigned integer
overflow. This vulnerability allowed attackers to cause a denial of
service (system crash) via unspecified vectors.
Todd Miller discovered that protobuf-c contained a possible NULL
dereference. This could cause a vulnerability that allowed attackers to
cause a denial of service (system crash) via unspecified vectors.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
protobuf-c: invalid arithmetic shift via the function parse_tag_and_wiretype may lead to DoS
vendor_redhat·2022-06-23·CVSS 5.5
CVE-2022-33070 [MEDIUM] CWE-400 protobuf-c: invalid arithmetic shift via the function parse_tag_and_wiretype may lead to DoS
protobuf-c: invalid arithmetic shift via the function parse_tag_and_wiretype may lead to DoS
Protobuf-c v1.4.0 was discovered to contain an invalid arithmetic shift via the function parse_tag_and_wiretype in protobuf-c/protobuf-c.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via unspecified vectors.
A flaw was found in protobuf-c. The issue occurs due to an invalid arithmetic shift via the parse_tag_and_wiretype in the protobuf-c/protobuf-c.c function. This flaw allows attackers to cause a denial of service (DoS) via unspecified vectors.
Statement: The vulnerability has been marked low as exploiting this vulnerability is highly unlikely to be possible as user input isn't taken by the vulnerable functions.
Mitigation: Mitigation for this issue is either not a
Microsoft
Protobuf-c v1.4.0 was discovered to contain an invalid arithmetic shift via the function parse_tag_and_wiretype in protobuf-c/protobuf-c.c. This vulnerability allows attackers to cause a Denial of Ser
vendor_msrc·2022-06-14·CVSS 5.5
CVE-2022-33070 [MEDIUM] Protobuf-c v1.4.0 was discovered to contain an invalid arithmetic shift via the function parse_tag_and_wiretype in protobuf-c/protobuf-c.c. This vulnerability allows attackers to cause a Denial of Ser
Protobuf-c v1.4.0 was discovered to contain an invalid arithmetic shift via the function parse_tag_and_wiretype in protobuf-c/protobuf-c.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via unspecified vectors.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional product
Debian
CVE-2022-33070: protobuf-c - Protobuf-c v1.4.0 was discovered to contain an invalid arithmetic shift via the ...
vendor_debian·2022·CVSS 5.5
CVE-2022-33070 [MEDIUM] CVE-2022-33070: protobuf-c - Protobuf-c v1.4.0 was discovered to contain an invalid arithmetic shift via the ...
Protobuf-c v1.4.0 was discovered to contain an invalid arithmetic shift via the function parse_tag_and_wiretype in protobuf-c/protobuf-c.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 1.4.1-1)
bullseye: open
forky: resolved (fixed in 1.4.1-1)
sid: resolved (fixed in 1.4.1-1)
trixie: resolved (fixed in 1.4.1-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/protobuf-c/protobuf-c/issues/506https://github.com/protobuf-c/protobuf-c/pull/508https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FFN2GHUEGTSHRD7J5PKQ5DRSJSEQ2IKN/https://github.com/protobuf-c/protobuf-c/issues/506https://github.com/protobuf-c/protobuf-c/pull/508https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FFN2GHUEGTSHRD7J5PKQ5DRSJSEQ2IKN/
2022-06-23
Published