Memory exhaustion in LZ4 decompression in UniRPC daemon
CVE-2023-28507

9.8CRITICAL

Key Information:

Vendor
CVE Published:
29 March 2023

What is CVE-2023-28507?

Rocket Software's UniData and UniVerse products are affected by a memory exhaustion vulnerability that occurs in their decompression routines. When these routines are executed, they allocate increasing amounts of memory which can lead to the exhaustion of available system memory. This malfunction can cause a forked process to crash, resulting in potential disruptions and performance issues in affected environments. Users of UniData and UniVerse should upgrade to the latest versions to mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

UniData Linux 0 < 8.2.43.3003

UniVerse Linux 0 < 11.3.5.1001

UniVerse Linux 0 < 12.2.1.2002

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ron Bowes
.