CVE-2023-22895HIGHCVSS 7.5fixed in rust-bzip2 0.4.4-1 (bookworm)2023
CVE-2023-22895 [HIGH] CVE-2023-22895: rust-bzip2 - The bzip2 crate before 0.4.4 for Rust allow attackers to cause a denial of servi...
The bzip2 crate before 0.4.4 for Rust allow attackers to cause a denial of service via a large file that triggers an integer overflow in mem.rs. NOTE: this is unrelated to the https://crates.io/crates/bzip2-rs product.
Scope: local
bookworm: resolved (fixed in 0.4.4-1)
bullseye: open
forky: resolved (fixed in 0.4.4-1)
sid: resolved (fixed in 0.4.4-1)
trixie: reso
debian