Alerts This Week
Warning Icon 1 914
Alerts This Week
Warning Icon 1 914

SUSE: 2022:2954-1 Important Update: Protobuf Denial of Service Issues

suse
Calendar Grey November 11, 2022
Dist Suse Esm H88
SUSE Docker Update Notification and critical security patch for protobuf tackling DoS vulnerabilities.
The container suse/sle15 was updated

Summary

Advisory ID: SUSE-SU-2022:3922-1 Released: Wed Nov 9 09:03:33 2022 Summary: Security update for protobuf Type: security Severity: important

References

References : 1194530 1203681 1204256 CVE-2021-22569 CVE-2022-1941 CVE-2022-3171

1194530,1203681,1204256,CVE-2021-22569,CVE-2022-1941,CVE-2022-3171

This update for protobuf fixes the following issues:

- CVE-2021-22569: Fixed Denial of Service in protobuf-java in the parsing procedure for binary data (bsc#1194530).

- CVE-2022-1941: Fix a potential DoS issue in protobuf-cpp and protobuf-python (bsc#1203681)

- CVE-2022-3171: Fix a potential DoS issue when parsing with binary data in protobuf-java (bsc#1204256)

The following package changes have been done:

- libprotobuf-lite20-3.9.2-150200.4.19.2 updated

Severity
important
Lowest
Low
Medium
High
Critical

Container Advisory ID : SUSE-CU-2022:2954-1
Container Tags : bci/bci-base:15.4 , bci/bci-base:15.4.27.14.11 , suse/sle15:15.4 , suse/sle15:15.4.27.14.11
Container Release : 27.14.11
Severity : important
Type : security

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here