e2jk / vallenato.fr

El Vallenatero Francés
https://vallenato.fr
GNU Affero General Public License v3.0
0 stars 0 forks source link

Update dependency protobuf to v3.19.5 [SECURITY] #410

Closed renovate[bot] closed 1 year ago

renovate[bot] commented 2 years ago

Mend Renovate

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
protobuf ==3.19.4 -> ==3.19.5 age adoption passing confidence

GitHub Vulnerability Alerts

CVE-2022-1941

Summary

A message parsing and memory management vulnerability in ProtocolBuffer’s C++ and Python implementations can trigger an out of memory (OOM) failure when processing a specially crafted message, which could lead to a denial of service (DoS) on services using the libraries.

Reporter: ClusterFuzz

Affected versions: All versions of C++ Protobufs (including Python) prior to the versions listed below.

Severity & Impact

As scored by google
Medium 5.7 - CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Asscored byt NIST
High 7.5 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

A small (~500 KB) malicious payload can be constructed which causes the running service to allocate more than 3GB of RAM.

Proof of Concept

For reproduction details, please refer to the unit test that identifies the specific inputs that exercise this parsing weakness.

Mitigation / Patching

Please update to the latest available versions of the following packages:


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.



This PR has been generated by Mend Renovate. View repository job log here.

codecov-commenter commented 2 years ago

Codecov Report

Merging #410 (b6e5a47) into master (0560ac1) will not change coverage. The diff coverage is n/a.

@@           Coverage Diff           @@
##           master     #410   +/-   ##
=======================================
  Coverage   94.41%   94.41%           
=======================================
  Files           4        4           
  Lines         573      573           
=======================================
  Hits          541      541           
  Misses         32       32           
Flag Coverage Δ
unittests 94.41% <ø> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.

:mega: We’re building smart automated test selection to slash your CI/CD build times. Learn more