Protobuf-c v1.4.0 was discovered to contain an invalid arithmetic shift via the function parsetagand_wiretype in protobuf-c/protobuf-c.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via unspecified vectors.
{ "binaries": [ { "binary_name": "libprotobuf-c-dev", "binary_version": "1.3.3-1ubuntu0.1" }, { "binary_name": "libprotobuf-c1", "binary_version": "1.3.3-1ubuntu0.1" }, { "binary_name": "libprotobuf-c1-dbgsym", "binary_version": "1.3.3-1ubuntu0.1" }, { "binary_name": "protobuf-c-compiler", "binary_version": "1.3.3-1ubuntu0.1" }, { "binary_name": "protobuf-c-compiler-dbgsym", "binary_version": "1.3.3-1ubuntu0.1" } ], "availability": "No subscription required" }
{ "binaries": [ { "binary_name": "sudo", "binary_version": "1.8.31-1ubuntu1.2" }, { "binary_name": "sudo-dbgsym", "binary_version": "1.8.31-1ubuntu1.2" }, { "binary_name": "sudo-ldap", "binary_version": "1.8.31-1ubuntu1.2" }, { "binary_name": "sudo-ldap-dbgsym", "binary_version": "1.8.31-1ubuntu1.2" } ], "availability": "No subscription required" }
{ "binaries": [ { "binary_name": "libprotobuf-c-dev", "binary_version": "1.3.3-1ubuntu2.1" }, { "binary_name": "libprotobuf-c1", "binary_version": "1.3.3-1ubuntu2.1" }, { "binary_name": "libprotobuf-c1-dbgsym", "binary_version": "1.3.3-1ubuntu2.1" }, { "binary_name": "protobuf-c-compiler", "binary_version": "1.3.3-1ubuntu2.1" }, { "binary_name": "protobuf-c-compiler-dbgsym", "binary_version": "1.3.3-1ubuntu2.1" } ], "availability": "No subscription required" }
{ "binaries": [ { "binary_name": "sudo", "binary_version": "1.9.9-1ubuntu2.2" }, { "binary_name": "sudo-dbgsym", "binary_version": "1.9.9-1ubuntu2.2" }, { "binary_name": "sudo-ldap", "binary_version": "1.9.9-1ubuntu2.2" }, { "binary_name": "sudo-ldap-dbgsym", "binary_version": "1.9.9-1ubuntu2.2" } ], "availability": "No subscription required" }