5.5
CVSSv3

CVE-2021-22570

Published: 26/01/2022 Updated: 07/11/2023
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 188
Vector: AV:L/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

A flaw was found in protobuf. The vulnerability occurs due to incorrect parsing of a NULL character in the proto symbol and leads to a Null pointer dereference. This flaw allows an malicious user to execute unauthorized code or commands, read memory, modify memory. (CVE-2021-22570)

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

google protobuf

debian debian linux 9.0

debian debian linux 10.0

debian debian linux 11.0

fedoraproject fedora 34

fedoraproject fedora 35

fedoraproject fedora 36

oracle mysql

netapp snapcenter -

netapp oncommand workflow automation -

netapp oncommand insight -

netapp active iq unified manager -

Vendor Advisories

Synopsis Moderate: Red Hat OpenStack Platform 1624 (protobuf) security update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for protobuf is now available for Red Hat OpenStack Platform 1624 (Train) Red Hat ...
Synopsis Moderate: Red Hat OpenStack Platform 1619 (protobuf) security update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for protobuf is now available for Red Hat OpenStack Platform 1619 (Train) for Red ...
Synopsis Moderate: protobuf security update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for protobuf is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as having a ...
Synopsis Moderate: OpenShift Container Platform 41120 security update Type/Severity Security Advisory: Moderate Topic Red Hat OpenShift Container Platform release 41120 is now available withupdates to packages and images that fix several bugs and add enhancementsRed Hat Product Security has rated this update as having a security impactof ...
Synopsis Moderate: protobuf security update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for protobuf is now available for Red Hat Enterprise Linux 9Red Hat Product Security has rated this update as having a ...
Synopsis Moderate: OpenShift Container Platform 4120 bug fix and security update Type/Severity Security Advisory: Moderate Topic Red Hat OpenShift Container Platform release 4120 is now available withupdates to packages and images that fix several bugs and add enhancementsThis release includes a security update for Red Hat OpenShift Cont ...
A flaw was found in protobuf The vulnerability occurs due to incorrect parsing of a NULL character in the proto symbol and leads to a Null pointer dereference This flaw allows an attacker to execute unauthorized code or commands, read memory, modify memory (CVE-2021-22570) ...
A flaw was found in protobuf The vulnerability occurs due to incorrect parsing of a NULL character in the proto symbol and leads to a Null pointer dereference This flaw allows an attacker to execute unauthorized code or commands, read memory, modify memory (CVE-2021-22570) ...
A flaw was found in protobuf The vulnerability occurs due to incorrect parsing of a NULL character in the proto symbol and leads to a Null pointer dereference This flaw allows an attacker to execute unauthorized code or commands, read memory, modify memory (CVE-2021-22570) ...
Nullptr dereference when a null char is present in a proto symbol The symbol is parsed incorrectly, leading to an unchecked call into the proto file's name during generation of the resulting error message Since the symbol is incorrectly parsed, the file is nullptr We recommend upgrading to version 3150 or greater ...
A flaw was found in protobuf The vulnerability occurs due to incorrect parsing of a NULL character in the proto symbol and leads to a Null pointer dereference This flaw allows an attacker to execute unauthorized code or commands, read memory, modify memory (CVE-2021-22570) ...
A flaw was found in protobuf The vulnerability occurs due to incorrect parsing of a NULL character in the proto symbol and leads to a Null pointer dereference This flaw allows an attacker to execute unauthorized code or commands, read memory, modify memory (CVE-2021-22570) ...

Github Repositories

A docker CLI toolbox for forensics investigations.

Docker Forensic Toolbox Informations Credential : forensic:forensic From : Debian Bookworm Slim Size : Around 900MB Time : Few minutes to build Depending on your system Trivy : 0 unfixed vulnerabilities Installation git clone htps://githubcom/MikeHorn-git/docker-forensic-toolboxgit cd docker-forensic-toolbox Docker Compose sudo d

Scans SBOMs for vulnerabilities with Grype

vulnerability-operator Scans SBOMs and Images for vulnerabilities Overview This operator scans all SBOMs from a git-repository for vulnerabilities using Grype The result-list can be emitted as JSON-file served via an endpoint and/or as Prometheus metrics There may be more targets in the future The scans are done periodically Kubernetes Compatibility The image cont

A Plug-n-Play "Universal" MapleStory Discord Bot

Lapis Lapis is a Plug-n-Play Azure v316 Discord Bot that is powered by Lazuli and discordpy Lapis is inspired by the MapleDiscBot project, but aims to be leaner and more layman-friendly Lapis accesses character and inventory attributes in AzureMSv316-based databases using the Lazuli API Current Status: Awaiting overhaul! The discordpy has breaking changes going from v1 to