UBUNTU-CVE-2022-33070

Source
https://ubuntu.com/security/CVE-2022-33070
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-33070.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2022-33070
Related
Published
2022-06-23T17:15:00Z
Modified
2024-10-15T14:10:00Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

Protobuf-c v1.4.0 was discovered to contain an invalid arithmetic shift via the function parsetagand_wiretype in protobuf-c/protobuf-c.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via unspecified vectors.

References

Affected packages

Ubuntu:Pro:14.04:LTS / pidgin

Package

Name
pidgin
Purl
pkg:deb/ubuntu/pidgin?arch=src?distro=trusty/esm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1:2.*

1:2.10.7-0ubuntu4.1
1:2.10.7-0ubuntu4.2
1:2.10.9-0ubuntu1
1:2.10.9-0ubuntu2
1:2.10.9-0ubuntu3
1:2.10.9-0ubuntu3.1
1:2.10.9-0ubuntu3.2
1:2.10.9-0ubuntu3.3
1:2.10.9-0ubuntu3.4

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:Pro:14.04:LTS / protobuf-c

Package

Name
protobuf-c
Purl
pkg:deb/ubuntu/protobuf-c?arch=src?distro=trusty/esm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

0.*

0.14-1ubuntu1
0.15-1
0.15-1build1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:Pro:16.04:LTS / argyll

Package

Name
argyll
Purl
pkg:deb/ubuntu/argyll?arch=src?distro=esm-apps/xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.7.0+repack-4
1.8.2+repack-1
1.8.3+repack-1
1.8.3+repack-2

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:Pro:16.04:LTS / libgadu

Package

Name
libgadu
Purl
pkg:deb/ubuntu/libgadu?arch=src?distro=esm-apps/xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1:1.*

1:1.12.1-2
1:1.12.1-2build1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:Pro:16.04:LTS / ocserv

Package

Name
ocserv
Purl
pkg:deb/ubuntu/ocserv?arch=src?distro=esm-apps/xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

0.*

0.10.7-1
0.10.10-1
0.10.10-1ubuntu1
0.10.11-1
0.10.11-1build1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:Pro:16.04:LTS / pidgin

Package

Name
pidgin
Purl
pkg:deb/ubuntu/pidgin?arch=src?distro=esm-apps/xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1:2.*

1:2.10.11-0ubuntu4
1:2.10.11-0ubuntu5
1:2.10.12-0ubuntu1
1:2.10.12-0ubuntu2
1:2.10.12-0ubuntu3
1:2.10.12-0ubuntu4
1:2.10.12-0ubuntu5
1:2.10.12-0ubuntu5.1
1:2.10.12-0ubuntu5.2

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:Pro:16.04:LTS / protobuf-c

Package

Name
protobuf-c
Purl
pkg:deb/ubuntu/protobuf-c?arch=src?distro=esm-apps/xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.0.2-1build2
1.1.1-1
1.2.1-1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:Pro:18.04:LTS / argyll

Package

Name
argyll
Purl
pkg:deb/ubuntu/argyll?arch=src?distro=esm-apps/bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.9.2+repack-1
1.9.2+repack-2

2.*

2.0.0+repack-1build1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:Pro:18.04:LTS / libgadu

Package

Name
libgadu
Purl
pkg:deb/ubuntu/libgadu?arch=src?distro=esm-apps/bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1:1.*

1:1.12.2-2
1:1.12.2-3

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:Pro:18.04:LTS / libsignal-protocol-c

Package

Name
libsignal-protocol-c
Purl
pkg:deb/ubuntu/libsignal-protocol-c?arch=src?distro=esm-apps/bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*

2.3.1+git20171007-2
2.3.1+git20171007-3

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:Pro:18.04:LTS / ocserv

Package

Name
ocserv
Purl
pkg:deb/ubuntu/ocserv?arch=src?distro=esm-apps/bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

0.*

0.11.6-2
0.11.9-1
0.11.9-1build1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:Pro:18.04:LTS / pidgin

Package

Name
pidgin
Purl
pkg:deb/ubuntu/pidgin?arch=src?distro=esm-apps/bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1:2.*

1:2.12.0-1ubuntu2
1:2.12.0-1ubuntu4

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:Pro:18.04:LTS / protobuf-c

Package

Name
protobuf-c
Purl
pkg:deb/ubuntu/protobuf-c?arch=src?distro=esm-apps/bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.2.1-2

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:20.04:LTS / argyll

Package

Name
argyll
Purl
pkg:deb/ubuntu/argyll?arch=src?distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*

2.0.1+repack-1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:20.04:LTS / ccextractor

Package

Name
ccextractor
Purl
pkg:deb/ubuntu/ccextractor?arch=src?distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

0.*

0.87+ds1-1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:20.04:LTS / libgadu

Package

Name
libgadu
Purl
pkg:deb/ubuntu/libgadu?arch=src?distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1:1.*

1:1.12.2-3
1:1.12.2-4

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:20.04:LTS / libsignal-protocol-c

Package

Name
libsignal-protocol-c
Purl
pkg:deb/ubuntu/libsignal-protocol-c?arch=src?distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*

2.3.2-2

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:20.04:LTS / ocserv

Package

Name
ocserv
Purl
pkg:deb/ubuntu/ocserv?arch=src?distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

0.*

0.12.2-3build1
0.12.2-3build2
0.12.5-1
0.12.6-1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:20.04:LTS / pidgin

Package

Name
pidgin
Purl
pkg:deb/ubuntu/pidgin?arch=src?distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1:2.*

1:2.13.0-2.2ubuntu1
1:2.13.0-2.2ubuntu2
1:2.13.0-2.2ubuntu3
1:2.13.0-2.2ubuntu4

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:20.04:LTS / protobuf-c

Package

Name
protobuf-c
Purl
pkg:deb/ubuntu/protobuf-c?arch=src?distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.3.3-1ubuntu0.1

Affected versions

1.*

1.3.1-1build1
1.3.2-1
1.3.3-1

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "medium",
    "binaries": [
        {
            "binary_version": "1.3.3-1ubuntu0.1",
            "binary_name": "libprotobuf-c-dev"
        },
        {
            "binary_version": "1.3.3-1ubuntu0.1",
            "binary_name": "libprotobuf-c1"
        },
        {
            "binary_version": "1.3.3-1ubuntu0.1",
            "binary_name": "libprotobuf-c1-dbgsym"
        },
        {
            "binary_version": "1.3.3-1ubuntu0.1",
            "binary_name": "protobuf-c-compiler"
        },
        {
            "binary_version": "1.3.3-1ubuntu0.1",
            "binary_name": "protobuf-c-compiler-dbgsym"
        }
    ]
}

Ubuntu:20.04:LTS / sudo

Package

Name
sudo
Purl
pkg:deb/ubuntu/sudo?arch=src?distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.8.31-1ubuntu1.2

Affected versions

1.*

1.8.27-1ubuntu4
1.8.29-1ubuntu1
1.8.31-1ubuntu1
1.8.31-1ubuntu1.1

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "medium",
    "binaries": [
        {
            "binary_version": "1.8.31-1ubuntu1.2",
            "binary_name": "sudo"
        },
        {
            "binary_version": "1.8.31-1ubuntu1.2",
            "binary_name": "sudo-dbgsym"
        },
        {
            "binary_version": "1.8.31-1ubuntu1.2",
            "binary_name": "sudo-ldap"
        },
        {
            "binary_version": "1.8.31-1ubuntu1.2",
            "binary_name": "sudo-ldap-dbgsym"
        }
    ]
}

Ubuntu:22.04:LTS / argyll

Package

Name
argyll
Purl
pkg:deb/ubuntu/argyll?arch=src?distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*

2.0.1+repack-2
2.2.0+repack-1
2.2.0+repack-1build1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:22.04:LTS / ccextractor

Package

Name
ccextractor
Purl
pkg:deb/ubuntu/ccextractor?arch=src?distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

0.*

0.88+ds1-1
0.93+ds2-1
0.93+ds2-1ubuntu1
0.93+ds2-2

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:22.04:LTS / libgadu

Package

Name
libgadu
Purl
pkg:deb/ubuntu/libgadu?arch=src?distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1:1.*

1:1.12.2-5
1:1.12.2-6

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:22.04:LTS / libpg-query

Package

Name
libpg-query
Purl
pkg:deb/ubuntu/libpg-query?arch=src?distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

13-2.*

13-2.1.0-1
13-2.1.0-2

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:22.04:LTS / libsignal-protocol-c

Package

Name
libsignal-protocol-c
Purl
pkg:deb/ubuntu/libsignal-protocol-c?arch=src?distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*

2.3.3-1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:22.04:LTS / ocserv

Package

Name
ocserv
Purl
pkg:deb/ubuntu/ocserv?arch=src?distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.1.2-2
1.1.3-1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:22.04:LTS / pidgin

Package

Name
pidgin
Purl
pkg:deb/ubuntu/pidgin?arch=src?distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1:2.*

1:2.14.1-1ubuntu1
1:2.14.8-1ubuntu1
1:2.14.8-1ubuntu2
1:2.14.8-1ubuntu2.1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:22.04:LTS / protobuf-c

Package

Name
protobuf-c
Purl
pkg:deb/ubuntu/protobuf-c?arch=src?distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.3.3-1ubuntu2.1

Affected versions

1.*

1.3.3-1build2
1.3.3-1ubuntu1
1.3.3-1ubuntu2

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "medium",
    "binaries": [
        {
            "binary_version": "1.3.3-1ubuntu2.1",
            "binary_name": "libprotobuf-c-dev"
        },
        {
            "binary_version": "1.3.3-1ubuntu2.1",
            "binary_name": "libprotobuf-c1"
        },
        {
            "binary_version": "1.3.3-1ubuntu2.1",
            "binary_name": "libprotobuf-c1-dbgsym"
        },
        {
            "binary_version": "1.3.3-1ubuntu2.1",
            "binary_name": "protobuf-c-compiler"
        },
        {
            "binary_version": "1.3.3-1ubuntu2.1",
            "binary_name": "protobuf-c-compiler-dbgsym"
        }
    ]
}

Ubuntu:22.04:LTS / sudo

Package

Name
sudo
Purl
pkg:deb/ubuntu/sudo?arch=src?distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.9.9-1ubuntu2.2

Affected versions

1.*

1.9.5p2-3ubuntu2
1.9.9-1ubuntu2
1.9.9-1ubuntu2.1

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "medium",
    "binaries": [
        {
            "binary_version": "1.9.9-1ubuntu2.2",
            "binary_name": "sudo"
        },
        {
            "binary_version": "1.9.9-1ubuntu2.2",
            "binary_name": "sudo-dbgsym"
        },
        {
            "binary_version": "1.9.9-1ubuntu2.2",
            "binary_name": "sudo-ldap"
        },
        {
            "binary_version": "1.9.9-1ubuntu2.2",
            "binary_name": "sudo-ldap-dbgsym"
        }
    ]
}

Ubuntu:24.10 / argyll

Package

Name
argyll
Purl
pkg:deb/ubuntu/argyll?arch=src?distro=oracular

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

3.*

3.1.0+repack-1build4
3.1.0+repack-1.1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:24.10 / libgadu

Package

Name
libgadu
Purl
pkg:deb/ubuntu/libgadu?arch=src?distro=oracular

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1:1.*

1:1.12.2-6.1build2

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:24.10 / libpg-query

Package

Name
libpg-query
Purl
pkg:deb/ubuntu/libpg-query?arch=src?distro=oracular

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

16-5.*

16-5.1.0-2

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:24.10 / libsignal-protocol-c

Package

Name
libsignal-protocol-c
Purl
pkg:deb/ubuntu/libsignal-protocol-c?arch=src?distro=oracular

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*

2.3.3-3

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:24.10 / ocserv

Package

Name
ocserv
Purl
pkg:deb/ubuntu/ocserv?arch=src?distro=oracular

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.2.4-1build2

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:24.10 / pidgin

Package

Name
pidgin
Purl
pkg:deb/ubuntu/pidgin?arch=src?distro=oracular

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1:2.*

1:2.14.13-1ubuntu2

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:24.04:LTS / argyll

Package

Name
argyll
Purl
pkg:deb/ubuntu/argyll?arch=src?distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*

2.3.1+repack-1ubuntu2

3.*

3.1.0+repack-1
3.1.0+repack-1build2
3.1.0+repack-1build3
3.1.0+repack-1build4

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:24.04:LTS / ccextractor

Package

Name
ccextractor
Purl
pkg:deb/ubuntu/ccextractor?arch=src?distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

0.*

0.94+ds1-3
0.94+ds1-3build2
0.94+ds1-3build3

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:24.04:LTS / libgadu

Package

Name
libgadu
Purl
pkg:deb/ubuntu/libgadu?arch=src?distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1:1.*

1:1.12.2-6
1:1.12.2-6.1
1:1.12.2-6.1build1
1:1.12.2-6.1build2

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:24.04:LTS / libpg-query

Package

Name
libpg-query
Purl
pkg:deb/ubuntu/libpg-query?arch=src?distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

15-4.*

15-4.2.3-1
15-4.2.3-2

16-5.*

16-5.1.0-2

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:24.04:LTS / libsignal-protocol-c

Package

Name
libsignal-protocol-c
Purl
pkg:deb/ubuntu/libsignal-protocol-c?arch=src?distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*

2.3.3-3

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:24.04:LTS / ocserv

Package

Name
ocserv
Purl
pkg:deb/ubuntu/ocserv?arch=src?distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.2.0-1
1.2.1-1
1.2.2-1
1.2.4-1
1.2.4-1build1
1.2.4-1build2

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:24.04:LTS / pidgin

Package

Name
pidgin
Purl
pkg:deb/ubuntu/pidgin?arch=src?distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1:2.*

1:2.14.12-1ubuntu1
1:2.14.12-1ubuntu2
1:2.14.13-1ubuntu1
1:2.14.13-1ubuntu2

Ecosystem specific

{
    "ubuntu_priority": "medium"
}