Vulnerability Description
Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a stack-based buffer overflow in the "udadmin" service that can lead to remote code execution as the root user.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Rocketsoftware | Unidata | <= 8.2.4 |
| Rocketsoftware | Universe | <= 11.3.5 |
| Linux | Linux Kernel | - |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/171853/Rocket-Software-Unidata-8.2.4-Build-
- https://www.rapid7.com/blog/post/2023/03/29/multiple-vulnerabilities-in-rocket-sThird Party Advisory
- http://packetstormsecurity.com/files/171853/Rocket-Software-Unidata-8.2.4-Build-
- https://www.rapid7.com/blog/post/2023/03/29/multiple-vulnerabilities-in-rocket-sThird Party Advisory
FAQ
What is CVE-2023-28502?
CVE-2023-28502 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a stack-based buffer overflow in the "udadmin" service that...
How severe is CVE-2023-28502?
CVE-2023-28502 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2023-28502?
Check the references section above for vendor advisories and patch information. Affected products include: Rocketsoftware Unidata, Rocketsoftware Universe, Linux Linux Kernel.