CVE-2015-5237 (NVD)

2017-09-25

protobuf allows remote authenticated attackers to cause a heap-based buffer overflow.

Products Protobuf
Type Out-of-bounds Write (CWE-787)
First patch - None (likely due to unavailable code)
Links https://lists.apache.org/thread.html/r42e47994734cd1980ef3e204a40555336e10cc80096927aca2f37d90%40%3Ccommits.pulsar.apache.org%3E
https://bugzilla.redhat.com/show_bug.cgi?id=1256426
https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org%3E
http://www.openwall.com/lists/oss-security/2015/08/27/2
https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.org%3E