CVE-2023-22895

Severity CVSS v4.0:
Pending analysis
Type:
CWE-190 Integer Overflow or Wraparound
Publication date:
10/01/2023
Last modified:
07/04/2025

Description

The bzip2 crate before 0.4.4 for Rust allow attackers to cause a denial of service via a large file that triggers an integer overflow in mem.rs. NOTE: this is unrelated to the https://crates.io/crates/bzip2-rs product.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:bzip2_project:bzip2:*:*:*:*:*:rust:*:* 0.4.4 (excluding)