Vulnerability Description
Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a memory-exhaustion issue, where a decompression routine will allocate increasing amounts of memory until all system memory is exhausted and the forked process crashes.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Rocketsoftware | Unidata | <= 8.2.4 |
| Rocketsoftware | Universe | <= 11.3.5 |
| Linux | Linux Kernel | - |
Related Weaknesses (CWE)
References
- https://www.rapid7.com/blog/post/2023/03/29/multiple-vulnerabilities-in-rocket-sThird Party Advisory
- https://www.rapid7.com/blog/post/2023/03/29/multiple-vulnerabilities-in-rocket-sThird Party Advisory
FAQ
What is CVE-2023-28507?
CVE-2023-28507 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a memory-exhaustion issue, where a decompression routine wi...
How severe is CVE-2023-28507?
CVE-2023-28507 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2023-28507?
Check the references section above for vendor advisories and patch information. Affected products include: Rocketsoftware Unidata, Rocketsoftware Universe, Linux Linux Kernel.