An issue in protobuf-java allowed the interleaving of com.google.protobuf.UnknownFieldSet fields in such a way that would be processed out of order. A small malicious payload can occupy the parser for several minutes by creating large numbers of short-lived objects that cause frequent, repeated pauses. We recommend upgrading libraries beyond the vulnerable versions.
{
"unresolved_ranges": [
{
"source": "CPE_STRING",
"cpes": [
"cpe:2.3:a:oracle:communications_cloud_native_core_console:1.9.0:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"last_affected": "1.9.0"
}
],
"vendor_product": "oracle:communications_cloud_native_core_console"
},
{
"source": "CPE_STRING",
"cpes": [
"cpe:2.3:a:oracle:communications_cloud_native_core_network_repository_function:1.15.0:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:communications_cloud_native_core_network_repository_function:1.15.1:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"last_affected": "1.15.0"
},
{
"last_affected": "1.15.1"
}
],
"vendor_product": "oracle:communications_cloud_native_core_network_repository_function"
},
{
"source": "CPE_STRING",
"cpes": [
"cpe:2.3:a:oracle:communications_cloud_native_core_policy:1.15.0:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"last_affected": "1.15.0"
}
],
"vendor_product": "oracle:communications_cloud_native_core_policy"
},
{
"source": "CPE_STRING",
"cpes": [
"cpe:2.3:a:oracle:spatial_and_graph_mapviewer:19c:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:spatial_and_graph_mapviewer:21c:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"last_affected": "19c"
},
{
"last_affected": "21c"
}
],
"vendor_product": "oracle:spatial_and_graph_mapviewer"
}
]
}{
"source": "CPE_RANGE",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "3.19.2"
},
{
"fixed": "3.16.1"
},
{
"fixed": "3.18.2"
},
{
"introduced": "3.18.0"
},
{
"fixed": "3.18.2"
},
{
"introduced": "3.19.0"
},
{
"fixed": "3.19.2"
}
],
"cpe": [
"cpe:2.3:a:google:google-protobuf:*:*:*:*:*:ruby:*:*",
"cpe:2.3:a:google:protobuf-java:*:*:*:*:*:*:*:*",
"cpe:2.3:a:google:protobuf-kotlin:*:*:*:*:*:*:*:*"
]
}