7.5
CVSSv3

CVE-2023-22895

Published: 10/01/2023 Updated: 07/11/2023
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

The bzip2 crate prior to 0.4.4 for Rust allow malicious users to cause a denial of service via a large file that triggers an integer overflow in mem.rs. NOTE: this is unrelated to the crates.io/crates/bzip2-rs product.

Vulnerable Product Search on Vulmon Subscribe to Product

bzip2 project bzip2

Vendor Advisories

Debian Bug report logs - #1029158 rust-bzip2: CVE-2023-22895 Package: src:rust-bzip2; Maintainer for src:rust-bzip2 is Debian Rust Maintainers <pkg-rust-maintainers@alioth-listsdebiannet>; Reported by: Moritz Mühlenhoff <jmm@inutilorg> Date: Wed, 18 Jan 2023 16:36:15 UTC Severity: important Tags: security, upstre ...