{"id":"UBUNTU-CVE-2022-33070","details":"Protobuf-c v1.4.0 was discovered to contain an invalid arithmetic shift via the function parse_tag_and_wiretype in protobuf-c/protobuf-c.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via unspecified vectors.","modified":"2026-05-20T16:06:43.539841849Z","published":"2022-06-23T17:15:00Z","related":["USN-5531-1","USN-5811-1"],"upstream":["CVE-2022-33070"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2022-33070"},{"type":"REPORT","url":"https://github.com/protobuf-c/protobuf-c/pull/508"},{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-5531-1"},{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-5811-1"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2022-33070"}],"affected":[{"package":{"name":"pidgin","ecosystem":"Ubuntu:14.04:LTS","purl":"pkg:deb/ubuntu/pidgin?arch=source&distro=trusty"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1:2.10.7-0ubuntu4.1","1:2.10.7-0ubuntu4.2","1:2.10.9-0ubuntu1","1:2.10.9-0ubuntu2","1:2.10.9-0ubuntu3","1:2.10.9-0ubuntu3.1","1:2.10.9-0ubuntu3.2","1:2.10.9-0ubuntu3.3","1:2.10.9-0ubuntu3.4"],"ecosystem_specific":{"binaries":[{"binary_name":"finch","binary_version":"1:2.10.9-0ubuntu3.4"},{"binary_name":"libpurple-bin","binary_version":"1:2.10.9-0ubuntu3.4"},{"binary_name":"libpurple0","binary_version":"1:2.10.9-0ubuntu3.4"},{"binary_version":"1:2.10.9-0ubuntu3.4","binary_name":"pidgin"},{"binary_name":"pidgin-data","binary_version":"1:2.10.9-0ubuntu3.4"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-33070.json"}},{"package":{"name":"protobuf-c","ecosystem":"Ubuntu:14.04:LTS","purl":"pkg:deb/ubuntu/protobuf-c?arch=source&distro=trusty"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.14-1ubuntu1","0.15-1","0.15-1build1"],"ecosystem_specific":{"binaries":[{"binary_version":"0.15-1build1","binary_name":"libprotobuf-c0"},{"binary_name":"protobuf-c-compiler","binary_version":"0.15-1build1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-33070.json"}},{"package":{"name":"argyll","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/argyll?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.7.0+repack-4","1.8.2+repack-1","1.8.3+repack-1","1.8.3+repack-2"],"ecosystem_specific":{"binaries":[{"binary_version":"1.8.3+repack-2","binary_name":"argyll"},{"binary_name":"argyll-ref","binary_version":"1.8.3+repack-2"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-33070.json"}},{"package":{"name":"libgadu","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/libgadu?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1:1.12.1-2","1:1.12.1-2build1"],"ecosystem_specific":{"binaries":[{"binary_name":"libgadu3","binary_version":"1:1.12.1-2build1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-33070.json"}},{"package":{"name":"ocserv","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/ocserv?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.10.7-1","0.10.10-1","0.10.10-1ubuntu1","0.10.11-1","0.10.11-1build1"],"ecosystem_specific":{"binaries":[{"binary_version":"0.10.11-1build1","binary_name":"ocserv"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-33070.json"}},{"package":{"name":"pidgin","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/pidgin?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1:2.10.11-0ubuntu4","1:2.10.11-0ubuntu5","1:2.10.12-0ubuntu1","1:2.10.12-0ubuntu2","1:2.10.12-0ubuntu3","1:2.10.12-0ubuntu4","1:2.10.12-0ubuntu5","1:2.10.12-0ubuntu5.1","1:2.10.12-0ubuntu5.2"],"ecosystem_specific":{"binaries":[{"binary_name":"finch","binary_version":"1:2.10.12-0ubuntu5.2"},{"binary_name":"libpurple-bin","binary_version":"1:2.10.12-0ubuntu5.2"},{"binary_name":"libpurple0","binary_version":"1:2.10.12-0ubuntu5.2"},{"binary_name":"pidgin","binary_version":"1:2.10.12-0ubuntu5.2"},{"binary_name":"pidgin-data","binary_version":"1:2.10.12-0ubuntu5.2"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-33070.json"}},{"package":{"name":"protobuf-c","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/protobuf-c?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.0.2-1build2","1.1.1-1","1.2.1-1"],"ecosystem_specific":{"binaries":[{"binary_version":"1.2.1-1","binary_name":"libprotobuf-c1"},{"binary_name":"protobuf-c-compiler","binary_version":"1.2.1-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-33070.json"}},{"package":{"name":"argyll","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/argyll?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.9.2+repack-1","1.9.2+repack-2","2.0.0+repack-1build1"],"ecosystem_specific":{"binaries":[{"binary_name":"argyll","binary_version":"2.0.0+repack-1build1"},{"binary_name":"argyll-ref","binary_version":"2.0.0+repack-1build1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-33070.json"}},{"package":{"name":"libgadu","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/libgadu?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1:1.12.2-2","1:1.12.2-3"],"ecosystem_specific":{"binaries":[{"binary_name":"libgadu3","binary_version":"1:1.12.2-3"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-33070.json"}},{"package":{"name":"libsignal-protocol-c","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/libsignal-protocol-c?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.3.1+git20171007-2","2.3.1+git20171007-3"],"ecosystem_specific":{"binaries":[{"binary_version":"2.3.1+git20171007-3","binary_name":"libsignal-protocol-c2"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-33070.json"}},{"package":{"name":"ocserv","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/ocserv?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.11.6-2","0.11.9-1","0.11.9-1build1"],"ecosystem_specific":{"binaries":[{"binary_name":"ocserv","binary_version":"0.11.9-1build1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-33070.json"}},{"package":{"name":"pidgin","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/pidgin?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1:2.12.0-1ubuntu2","1:2.12.0-1ubuntu4"],"ecosystem_specific":{"binaries":[{"binary_name":"finch","binary_version":"1:2.12.0-1ubuntu4"},{"binary_name":"libpurple-bin","binary_version":"1:2.12.0-1ubuntu4"},{"binary_name":"libpurple0","binary_version":"1:2.12.0-1ubuntu4"},{"binary_name":"pidgin","binary_version":"1:2.12.0-1ubuntu4"},{"binary_version":"1:2.12.0-1ubuntu4","binary_name":"pidgin-data"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-33070.json"}},{"package":{"name":"protobuf-c","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/protobuf-c?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.2.1-2"],"ecosystem_specific":{"binaries":[{"binary_version":"1.2.1-2","binary_name":"libprotobuf-c1"},{"binary_name":"protobuf-c-compiler","binary_version":"1.2.1-2"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-33070.json"}},{"package":{"name":"protobuf-c","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/protobuf-c?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.3.3-1ubuntu0.1"}]}],"versions":["1.3.1-1build1","1.3.2-1","1.3.3-1"],"ecosystem_specific":{"binaries":[{"binary_name":"libprotobuf-c1","binary_version":"1.3.3-1ubuntu0.1"},{"binary_version":"1.3.3-1ubuntu0.1","binary_name":"protobuf-c-compiler"}],"availability":"No subscription required"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-33070.json"}},{"package":{"name":"argyll","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/argyll?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.0.1+repack-1"],"ecosystem_specific":{"binaries":[{"binary_name":"argyll","binary_version":"2.0.1+repack-1"},{"binary_version":"2.0.1+repack-1","binary_name":"argyll-ref"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-33070.json"}},{"package":{"name":"ccextractor","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/ccextractor?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.87+ds1-1"],"ecosystem_specific":{"binaries":[{"binary_name":"ccextractor","binary_version":"0.87+ds1-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-33070.json"}},{"package":{"name":"libgadu","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/libgadu?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1:1.12.2-3","1:1.12.2-4"],"ecosystem_specific":{"binaries":[{"binary_name":"libgadu3","binary_version":"1:1.12.2-4"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-33070.json"}},{"package":{"name":"libsignal-protocol-c","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/libsignal-protocol-c?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.3.2-2"],"ecosystem_specific":{"binaries":[{"binary_version":"2.3.2-2","binary_name":"libsignal-protocol-c2.3.2"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-33070.json"}},{"package":{"name":"ocserv","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/ocserv?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.12.2-3build1","0.12.2-3build2","0.12.5-1","0.12.6-1"],"ecosystem_specific":{"binaries":[{"binary_name":"ocserv","binary_version":"0.12.6-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-33070.json"}},{"package":{"name":"pidgin","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/pidgin?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1:2.13.0-2.2ubuntu1","1:2.13.0-2.2ubuntu2","1:2.13.0-2.2ubuntu3","1:2.13.0-2.2ubuntu4"],"ecosystem_specific":{"binaries":[{"binary_name":"finch","binary_version":"1:2.13.0-2.2ubuntu4"},{"binary_version":"1:2.13.0-2.2ubuntu4","binary_name":"libpurple-bin"},{"binary_name":"libpurple0","binary_version":"1:2.13.0-2.2ubuntu4"},{"binary_version":"1:2.13.0-2.2ubuntu4","binary_name":"pidgin"},{"binary_version":"1:2.13.0-2.2ubuntu4","binary_name":"pidgin-data"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-33070.json"}},{"package":{"name":"argyll","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/argyll?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.0.1+repack-2","2.2.0+repack-1","2.2.0+repack-1build1"],"ecosystem_specific":{"binaries":[{"binary_version":"2.2.0+repack-1build1","binary_name":"argyll"},{"binary_name":"argyll-ref","binary_version":"2.2.0+repack-1build1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-33070.json"}},{"package":{"name":"ccextractor","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/ccextractor?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.88+ds1-1","0.93+ds2-1","0.93+ds2-1ubuntu1","0.93+ds2-2"],"ecosystem_specific":{"binaries":[{"binary_version":"0.93+ds2-2","binary_name":"ccextractor"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-33070.json"}},{"package":{"name":"libgadu","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/libgadu?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1:1.12.2-5","1:1.12.2-6"],"ecosystem_specific":{"binaries":[{"binary_name":"libgadu3","binary_version":"1:1.12.2-6"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-33070.json"}},{"package":{"name":"libpg-query","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/libpg-query?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["13-2.1.0-1","13-2.1.0-2"],"ecosystem_specific":{"binaries":[{"binary_version":"13-2.1.0-2","binary_name":"libpg-query1302.1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-33070.json"}},{"package":{"name":"libsignal-protocol-c","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/libsignal-protocol-c?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.3.3-1"],"ecosystem_specific":{"binaries":[{"binary_name":"libsignal-protocol-c2.3.2","binary_version":"2.3.3-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-33070.json"}},{"package":{"name":"ocserv","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/ocserv?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.1.2-2","1.1.3-1"],"ecosystem_specific":{"binaries":[{"binary_name":"ocserv","binary_version":"1.1.3-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-33070.json"}},{"package":{"name":"pidgin","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/pidgin?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1:2.14.1-1ubuntu1","1:2.14.8-1ubuntu1","1:2.14.8-1ubuntu2","1:2.14.8-1ubuntu2.1"],"ecosystem_specific":{"binaries":[{"binary_name":"finch","binary_version":"1:2.14.8-1ubuntu2.1"},{"binary_version":"1:2.14.8-1ubuntu2.1","binary_name":"libpurple-bin"},{"binary_name":"libpurple0","binary_version":"1:2.14.8-1ubuntu2.1"},{"binary_version":"1:2.14.8-1ubuntu2.1","binary_name":"pidgin"},{"binary_name":"pidgin-data","binary_version":"1:2.14.8-1ubuntu2.1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-33070.json"}},{"package":{"name":"protobuf-c","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/protobuf-c?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.3.3-1ubuntu2.1"}]}],"versions":["1.3.3-1build2","1.3.3-1ubuntu1","1.3.3-1ubuntu2"],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_name":"libprotobuf-c1","binary_version":"1.3.3-1ubuntu2.1"},{"binary_version":"1.3.3-1ubuntu2.1","binary_name":"protobuf-c-compiler"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-33070.json"}},{"package":{"name":"sudo","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/sudo?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.9.9-1ubuntu2.2"}]}],"versions":["1.9.5p2-3ubuntu2","1.9.9-1ubuntu2","1.9.9-1ubuntu2.1"],"ecosystem_specific":{"binaries":[{"binary_name":"sudo","binary_version":"1.9.9-1ubuntu2.2"},{"binary_name":"sudo-ldap","binary_version":"1.9.9-1ubuntu2.2"}],"availability":"No subscription required"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-33070.json"}},{"package":{"name":"argyll","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/argyll?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.3.1+repack-1ubuntu2","3.1.0+repack-1","3.1.0+repack-1build2","3.1.0+repack-1build3","3.1.0+repack-1build4"],"ecosystem_specific":{"binaries":[{"binary_name":"argyll","binary_version":"3.1.0+repack-1build4"},{"binary_version":"3.1.0+repack-1build4","binary_name":"argyll-ref"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-33070.json"}},{"package":{"name":"ccextractor","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/ccextractor?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.94+ds1-3","0.94+ds1-3build2","0.94+ds1-3build3"],"ecosystem_specific":{"binaries":[{"binary_name":"ccextractor","binary_version":"0.94+ds1-3build3"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-33070.json"}},{"package":{"name":"libgadu","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/libgadu?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1:1.12.2-6","1:1.12.2-6.1","1:1.12.2-6.1build1","1:1.12.2-6.1build2"],"ecosystem_specific":{"binaries":[{"binary_name":"libgadu3t64","binary_version":"1:1.12.2-6.1build2"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-33070.json"}},{"package":{"name":"libpg-query","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/libpg-query?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["15-4.2.3-1","15-4.2.3-2","16-5.1.0-2"],"ecosystem_specific":{"binaries":[{"binary_name":"libpg-query1605.1","binary_version":"16-5.1.0-2"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-33070.json"}},{"package":{"name":"libsignal-protocol-c","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/libsignal-protocol-c?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.3.3-3"],"ecosystem_specific":{"binaries":[{"binary_name":"libsignal-protocol-c2.3.2","binary_version":"2.3.3-3"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-33070.json"}},{"package":{"name":"ocserv","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/ocserv?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.2.0-1","1.2.1-1","1.2.2-1","1.2.4-1","1.2.4-1build1","1.2.4-1build2"],"ecosystem_specific":{"binaries":[{"binary_name":"ocserv","binary_version":"1.2.4-1build2"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-33070.json"}},{"package":{"name":"pidgin","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/pidgin?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1:2.14.12-1ubuntu1","1:2.14.12-1ubuntu2","1:2.14.13-1ubuntu1","1:2.14.13-1ubuntu2"],"ecosystem_specific":{"binaries":[{"binary_name":"finch","binary_version":"1:2.14.13-1ubuntu2"},{"binary_version":"1:2.14.13-1ubuntu2","binary_name":"libpurple-bin"},{"binary_name":"libpurple0t64","binary_version":"1:2.14.13-1ubuntu2"},{"binary_name":"pidgin","binary_version":"1:2.14.13-1ubuntu2"},{"binary_name":"pidgin-data","binary_version":"1:2.14.13-1ubuntu2"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-33070.json"}},{"package":{"name":"argyll","ecosystem":"Ubuntu:25.10","purl":"pkg:deb/ubuntu/argyll?arch=source&distro=questing"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["3.1.0+repack-1.1","3.3.0+repack-1"],"ecosystem_specific":{"binaries":[{"binary_version":"3.3.0+repack-1","binary_name":"argyll"},{"binary_name":"argyll-ref","binary_version":"3.3.0+repack-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-33070.json"}},{"package":{"name":"libgadu","ecosystem":"Ubuntu:25.10","purl":"pkg:deb/ubuntu/libgadu?arch=source&distro=questing"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1:1.12.2-6.1build2","1:1.12.2-6.1build3"],"ecosystem_specific":{"binaries":[{"binary_version":"1:1.12.2-6.1build3","binary_name":"libgadu3t64"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-33070.json"}},{"package":{"name":"libpg-query","ecosystem":"Ubuntu:25.10","purl":"pkg:deb/ubuntu/libpg-query?arch=source&distro=questing"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["17-6.0.0-1","17-6.1.0-1"],"ecosystem_specific":{"binaries":[{"binary_name":"libpg-query1706.0","binary_version":"17-6.1.0-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-33070.json"}},{"package":{"name":"libsignal-protocol-c","ecosystem":"Ubuntu:25.10","purl":"pkg:deb/ubuntu/libsignal-protocol-c?arch=source&distro=questing"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.3.3-6"],"ecosystem_specific":{"binaries":[{"binary_name":"libsignal-protocol-c2.3.2","binary_version":"2.3.3-6"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-33070.json"}},{"package":{"name":"ocserv","ecosystem":"Ubuntu:25.10","purl":"pkg:deb/ubuntu/ocserv?arch=source&distro=questing"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.3.0-1","1.3.0-2"],"ecosystem_specific":{"binaries":[{"binary_version":"1.3.0-2","binary_name":"ocserv"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-33070.json"}},{"package":{"name":"pidgin","ecosystem":"Ubuntu:25.10","purl":"pkg:deb/ubuntu/pidgin?arch=source&distro=questing"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1:2.14.14-1ubuntu1","1:2.14.14-1ubuntu2"],"ecosystem_specific":{"binaries":[{"binary_name":"finch","binary_version":"1:2.14.14-1ubuntu2"},{"binary_name":"libpurple-bin","binary_version":"1:2.14.14-1ubuntu2"},{"binary_version":"1:2.14.14-1ubuntu2","binary_name":"libpurple0t64"},{"binary_version":"1:2.14.14-1ubuntu2","binary_name":"pidgin"},{"binary_version":"1:2.14.14-1ubuntu2","binary_name":"pidgin-data"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-33070.json"}},{"package":{"name":"argyll","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/argyll?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["3.3.0+repack-1","3.3.0+repack-1.1"],"ecosystem_specific":{"binaries":[{"binary_version":"3.3.0+repack-1.1","binary_name":"argyll"},{"binary_name":"argyll-ref","binary_version":"3.3.0+repack-1.1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-33070.json"}},{"package":{"name":"libgadu","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/libgadu?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1:1.12.2-6.1build3","1:1.12.2-7"],"ecosystem_specific":{"binaries":[{"binary_name":"libgadu3t64","binary_version":"1:1.12.2-7"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-33070.json"}},{"package":{"name":"libpg-query","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/libpg-query?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["17-6.1.0-1","17-6.2.0-1","17-6.2.0-2","17-6.2.1-1","17-6.2.2-1"],"ecosystem_specific":{"binaries":[{"binary_name":"libpg-query1706.0","binary_version":"17-6.2.2-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-33070.json"}},{"package":{"name":"libsignal-protocol-c","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/libsignal-protocol-c?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.3.3-6","2.3.3-6.1"],"ecosystem_specific":{"binaries":[{"binary_name":"libsignal-protocol-c2.3.2","binary_version":"2.3.3-6.1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-33070.json"}},{"package":{"name":"ocserv","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/ocserv?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.3.0-2","1.3.0-3"],"ecosystem_specific":{"binaries":[{"binary_version":"1.3.0-3","binary_name":"ocserv"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-33070.json"}},{"package":{"name":"pidgin","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/pidgin?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1:2.14.14-1ubuntu2","1:2.14.14-1ubuntu3"],"ecosystem_specific":{"binaries":[{"binary_name":"finch","binary_version":"1:2.14.14-1ubuntu3"},{"binary_version":"1:2.14.14-1ubuntu3","binary_name":"libpurple-bin"},{"binary_name":"libpurple0t64","binary_version":"1:2.14.14-1ubuntu3"},{"binary_version":"1:2.14.14-1ubuntu3","binary_name":"pidgin"},{"binary_name":"pidgin-data","binary_version":"1:2.14.14-1ubuntu3"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-33070.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"},{"type":"Ubuntu","score":"medium"}]}