CVE-2022-33070 is a Denial of Service (DoS) vulnerability in Protobuf-c v1.4.0, specifically an invalid arithmetic shift in the parse_tag_and_wiretype function, affecting fedoraproject and protobuf_c_project distributions. Rated Medium (CVSS 5.5), it requires local access and user interaction for an attacker to trigger the DoS. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.4.0CPE matchmatch criteria | cpe:2.3:a:protobuf-c_project:protobuf-c:1.4.0:*:*:*:*:*:*:* | ||
36CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
protobuf-c: invalid arithmetic shift via the function parse_tag_and_wiretype may lead to DoS
Jun 23, 2022Protobuf-c v1.4.0 was discovered to contain an invalid arithmetic shift via the function parse_tag_and_wiretype in protobuf-c/protobuf-c.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via unspecified vectors.
Jun 14, 2022