Insecure functionality In protobuf
Description
An issue in protobuf-java allowed the interleaving of com.google.protobuf.UnknownFieldSet fields in such a way that would be processed out of order. A small malicious payload can occupy the parser for several minutes by creating large numbers of short-lived objects that cause frequent, repeated pauses. We recommend upgrading libraries beyond the vulnerable versions.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
debian 12 | 3.21.9-3 | ||
debian 14 | 3.21.9-3 | ||
maven | 3.16.1, 3.18.2, 3.19.2 | ||
debian 13 | 3.21.9-3 | ||
rubygems | 3.19.2 | ||
maven | 3.18.2, 3.19.2 |
Aliases
1. 2. 3. 4. 5. 6. 7.
References
1. 2. 3. 4. 5. 6. 7.