CVE-2021-22570

Updated: 2023-03-10 12:28:07.061403

Description:

Nullptr dereference when a null char is present in a proto symbol. The symbol is parsed incorrectly, leading to an unchecked call into the proto file's name during generation of the resulting error message. Since the symbol is incorrectly parsed, the file is nullptr. We recommend upgrading to version 3.15.0 or greater.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x LOW 2.1
CVSS Version 3.x MEDIUM 5.5

Status

OS name Project name Version Score Severity Status Errata Last updated
CentOS 6 ELS mysql 5.1.73 5.5 MEDIUM Not Vulnerable 2022-06-07 11:40:44
CentOS 8.4 ELS mysql 8.0.26 5.5 MEDIUM Not Vulnerable 2022-11-09 07:05:41
CentOS 8.5 ELS mysql 8.0.26 5.5 MEDIUM Not Vulnerable 2022-11-09 07:05:41
CloudLinux 6 ELS mysql 5.1.73 5.5 MEDIUM Not Vulnerable 2022-06-07 11:40:44
Oracle Linux 6 ELS mysql 5.1.73 5.5 MEDIUM Not Vulnerable 2022-06-07 11:40:44
Ubuntu 16.04 ELS mysql 5.7.33-0 5.5 MEDIUM Not Vulnerable 2022-06-07 11:40:44
Ubuntu 18.04 ELS mysql 5.7.41-0 5.5 MEDIUM Needs Triage 2023-03-14 03:24:35