CVE-2023-22895

CVSS V2 None CVSS V3 None
Description
The bzip2 crate before 0.4.4 for Rust allow attackers to cause a denial of service via a large file that triggers an integer overflow in mem.rs. NOTE: this is unrelated to the https://crates.io/crates/bzip2-rs product.
Overview
  • CVE ID
  • CVE-2023-22895
  • Assigner
  • cve@mitre.org
  • Vulnerability Status
  • Modified
  • Published Version
  • 2023-01-10T01:15:10
  • Last Modified Date
  • 2023-03-11T06:15:53
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
cpe:2.3:a:bzip2_project:bzip2:*:*:*:*:*:rust:*:* 1 OR 0.4.4
History
Created Old Value New Value Data Type Notes
2023-01-10 01:19:38 Added to TrackCVE
2023-01-10 14:18:48 2023-01-10T13:36:07 CVE Modified Date updated
2023-01-10 14:18:48 Received Awaiting Analysis Vulnerability Status updated
2023-01-12 18:17:15 Awaiting Analysis Undergoing Analysis Vulnerability Status updated
2023-01-13 09:16:51 2023-01-13T06:33:12 CVE Modified Date updated
2023-01-13 09:16:51 Undergoing Analysis Analyzed Vulnerability Status updated
2023-01-13 09:16:53 Weakness Enumeration new
2023-01-13 09:16:55 CPE Information updated
2023-03-07 03:18:53 2023-03-07T03:15:47 CVE Modified Date updated
2023-03-07 03:18:53 Analyzed Modified Vulnerability Status updated
2023-03-07 03:18:54 References updated
2023-03-07 05:16:58 2023-03-07T04:15:08 CVE Modified Date updated
2023-03-07 05:16:58 References updated
2023-03-11 07:14:29 2023-03-11T06:15:53 CVE Modified Date updated
2023-03-11 07:14:30 References updated