CVE-2023-28448 describes an out-of-bounds memory access vulnerability in the 'Versionize::deserialize' implementation of the 'versionize' Rust crate, specifically affecting 'vmm_sys_utils::fam::FamStructWrapper'. This flaw, present since version 0.1.1, could allow an unauthenticated attacker to cause a denial of service. The vulnerability has a CVSS score of 7.5 (HIGH) due to its network-based attack vector and low attack complexity, with no confidentiality or integrity impact but high availability impact. Currently, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0.1.1, < 0.1.10CPE matchmatch criteria | cpe:2.3:a:versionize_project:versionize:*:*:*:*:*:rust:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2023-28448
Apr 11, 2023Versionize::deserialize implementation for FamStructWrapper<T> is lacking bound checks, potentially leading to out of bounds memory accesses
Mar 24, 2023Versionize is lacking bound checks potentially leading to out of bounds memory access
Mar 14, 2023