CVE-2023-28504: Stack buffer overflow in UniRPC library function
Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a stack-based buffer overflow that can lead to remote code execution as the root user.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-28504?
The severity of CVE-2023-28504 is rated as critical with a score of 9.8.
How do I fix CVE-2023-28504?
To fix CVE-2023-28504, upgrade Rocket Software UniData to version 8.2.4 build 3003 or newer, and UniVerse to version 11.3.5 build 1001 or newer.
What types of vulnerabilities are associated with CVE-2023-28504?
CVE-2023-28504 involves stack-based buffer overflow vulnerabilities which can lead to remote code execution.
Which versions of Rocket Software are affected by CVE-2023-28504?
CVE-2023-28504 affects Rocket Software UniData versions prior to 8.2.4 and UniVerse versions prior to 11.3.5 and versions from 12.0.0 to 12.2.1.
What could be the potential impact of CVE-2023-28504?
The potential impact of CVE-2023-28504 includes remote code execution as the root user, compromising the integrity and security of the system.