MEDIUM · 6.5

CVE-2021-22570

Nullptr dereference when a null char is present in a proto symbol. The symbol is parsed incorrectly, leading to an unchecked call into the proto file's name during generation of the resulting error me...

Vulnerability Description

Nullptr dereference when a null char is present in a proto symbol. The symbol is parsed incorrectly, leading to an unchecked call into the proto file's name during generation of the resulting error message. Since the symbol is incorrectly parsed, the file is nullptr. We recommend upgrading to version 3.15.0 or greater.

CVSS Score

6.5

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
GoogleProtobuf< 3.15.0
DebianDebian Linux9.0
FedoraprojectFedora34
OracleMysql<= 8.0.28
NetappActive Iq Unified Manager-
NetappOncommand Insight-
NetappOncommand Workflow Automation-
NetappSnapcenter-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-22570?

CVE-2021-22570 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Nullptr dereference when a null char is present in a proto symbol. The symbol is parsed incorrectly, leading to an unchecked call into the proto file's name during generation of the resulting error me...

How severe is CVE-2021-22570?

CVE-2021-22570 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-22570?

Check the references section above for vendor advisories and patch information. Affected products include: Google Protobuf, Debian Debian Linux, Fedoraproject Fedora, Oracle Mysql, Netapp Active Iq Unified Manager.