Skip to content

Advisory GHSA-jwvw-v7c5-m82h - Clarification required on ecosystems impacted #5796

Open
@somakdutta

Description

@somakdutta

Hello,

Writing to talk about GHSA-jwvw-v7c5-m82h

For protobuf-java which specifically talks about "protobuf allows remote authenticated attackers to cause a heap-based buffer overflow."

Question : Given the advisory speaks about heap based buffer overflows, how would memory safe languages such as Java be impacted.

Information on this specific vulnerability and how it may affect java ecosystem is quite sparse.

I had reached out on protobuf forums with the same question - you can see further details here https://groups.google.com/g/protobuf/c/vvP4uajRE60/m/wRl8395mBwAJ

Based on the above clarification, would you say it is sufficient information to mark GHSA-jwvw-v7c5-m82h as affecting only C++ ecosystems.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions