CVE-2023-28507: Memory exhaustion in LZ4 decompression in UniRPC daemon
Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a memory-exhaustion issue, where a decompression routine will allocate increasing amounts of memory until all system memory is exhausted and the forked process crashes.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-28507?
CVE-2023-28507 is classified as a memory exhaustion vulnerability that can lead to significant system resource depletion.
How do I fix CVE-2023-28507?
To fix CVE-2023-28507, upgrade Rocket Software UniData to version 8.2.4 build 3003 or UniVerse to versions 11.3.5 build 1001 or 12.2.1 build 2002 or later.
What software is affected by CVE-2023-28507?
CVE-2023-28507 affects Rocket Software UniData versions prior to 8.2.4 and UniVerse versions prior to 11.3.5 and 12.2.1.
What happens if CVE-2023-28507 is exploited?
Exploitation of CVE-2023-28507 can result in the allocation of increasing amounts of memory, leading to system memory exhaustion and process failures.
When was CVE-2023-28507 disclosed?
CVE-2023-28507 was disclosed in 2023 as a part of an update addressing multiple vulnerabilities in Rocket Software.