Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Vulnerability: Google.Protobuf-3.7.0.0.dll #121

Open
tdashworth opened this issue Jul 4, 2022 · 0 comments
Open

Vulnerability: Google.Protobuf-3.7.0.0.dll #121

tdashworth opened this issue Jul 4, 2022 · 0 comments

Comments

@tdashworth
Copy link
Contributor

Vulnerability Library Description Top Fix Exists In Build Definitions
High7.5CVE-2021-22570Jan-26-2022 Google.Protobuf-3.7.0.0.dll Nullptr dereference when a null char is present in a proto symbol. The symbol is parsed incorrectly, leading to an unchecked call into the proto file's name during generation of the resulting error message. Since the symbol is incorrectly parsed, the file is nullptr. We recommend upgrading to version 3.15.0 or greater. Upgrade to version Google.Protobuf - 3.15.0GHSA-77rm-9x9h-xj3g Capgemini.PowerApps.SpecFlowBindings, Capgemini.PowerApps.SpecFlowBindings PR
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant