The bzip2 crate before 0.4.4 for Rust allow attackers to cause a denial of service via a large file that triggers an integer overflow in mem.rs
. NOTE: this is unrelated to the https://crates.io/crates/bzip2-rs product.
{ "nvd_published_at": "2023-01-10T01:15:00Z", "cwe_ids": [ "CWE-190" ], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2023-01-10T22:10:17Z" }