• 公告ID (KylinSec-SA-2022-1864)

摘要:

Nullptr dereference when a null char is present in a proto symbol. The symbol is parsed incorrectly, leading to an unchecked call into the proto file s name during generation of the resulting error message. Since the symbol is incorrectly parsed, the file is nullptr. We recommend upgrading to version 3.15.0 or greater.

安全等级: Low

公告ID: KylinSec-SA-2022-1864

发布日期: 2022年8月11日

关联CVE: CVE-2021-22570  

  • 详细介绍

1. 漏洞描述

   

Nullptr dereference when a null char is present in a proto symbol. The symbol is parsed incorrectly, leading to an unchecked call into the proto file s name during generation of the resulting error message. Since the symbol is incorrectly parsed, the file is nullptr. We recommend upgrading to version 3.15.0 or greater.

2. 影响范围

cve名称 产品 组件 是否受影响
CVE-2021-22570 KY3.4-4A linux-sgx Unaffected
CVE-2021-22570 KY3.4-5A linux-sgx Unaffected
CVE-2021-22570 KY3.5.1 linux-sgx Unaffected

3. 影响组件

    无

4. 修复版本

    无

5. 修复方法

   无

6. 下载链接

    无
上一篇:KylinSec-SA-2022-1863 下一篇:KylinSec-SA-2022-1865