cbcvebase.
CVE-2022-48468
published 2023-04-13

CVE-2022-48468: protobuf-c before 1.4.1 has an unsigned integer overflow in parse_required_member.

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.37%
29.6th percentile
protobuf-c before 1.4.1 has an unsigned integer overflow in parse_required_member.

Affected

12 ranges
VendorProductVersion rangeFixed in
debianlibsignal-protocol-c< libsignal-protocol-c 2.3.3-3 (bookworm)libsignal-protocol-c 2.3.3-3 (bookworm)
debianprotobuf-c< libsignal-protocol-c 2.3.3-3 (bookworm)libsignal-protocol-c 2.3.3-3 (bookworm)
msrccbl2_protobuf-c_1.4.1-1_on_cbl_mariner_2.0
msrccbl_mariner_1.0_arm
msrccbl_mariner_1.0_x64
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64
msrccm1_protobuf-c_1.3.2-2_on_cbl_mariner_1.0
protobuf-c_projectprotobuf-c< 1.4.11.4.1
protobuf-c_projectprotobuf-c>= 0 < 1.4.1-11.4.1-1
protobuf-c_projectprotobuf-c>= 0 < 1.4.1-11.4.1-1
protobuf-c_projectprotobuf-c>= 0 < 1.4.1-11.4.1-1

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.