UbuntuUpdates.org

Package "protobuf"

Name: protobuf

Description:

This package is just an umbrella for a group of other packages, it has no description.
Description samples from packages in group:

  • protocol buffers C++ library (development files) and proto files
  • protocol buffers C++ library (lite version)
  • protocol buffers C++ library
  • protocol buffers compiler library (development files)

Latest version: 3.21.12-8.2ubuntu0.1
Release: noble (24.04)
Level: updates
Repository: main

Links



Other versions of "protobuf" in Noble

Repository Area Version
base universe 3.21.12-8.2build1
base main 3.21.12-8.2build1
security main 3.21.12-8.2ubuntu0.1
security universe 3.21.12-8.2ubuntu0.1
updates universe 3.21.12-8.2ubuntu0.1

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 3.21.12-8.2ubuntu0.1 2025-04-14 18:07:05 UTC

  protobuf (3.21.12-8.2ubuntu0.1) noble-security; urgency=medium

  * SECURITY UPDATE: Stack overflow.
    - debian/patches/CVE-2024-7254-*.patch: Add recursion checks and recursion
      limit in .../protobuf/ArrayDecoders.java,
      .../protobuf/CodedInputStream.java, .../protobuf/MessageSchema.java, and
      .../protobuf/MessageSetSchema.java. Add tests.
    - CVE-2024-7254

 -- Hlib Korzhynskyy <email address hidden> Mon, 07 Apr 2025 12:24:21 -0230

CVE-2024-7254 Any project that parses untrusted Protocol Buffers data containing an arbitrary number of nested groups / series of SGROUP tags can corrupted by exce



About   -   Send Feedback to @ubuntu_updates