CRITICAL
Heap buffer overflow in unirpcd
Published Mar 29, 2023
9.8
CRITICALCVSS 3.1
EPSS 1.42%
Description
Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a heap-based buffer overflow in the unirpcd daemon that, if successfully exploited, can lead to remote code execution as the root user.
Affected products
-
- Version 0StatusaffectedConstraints<8.2.4.3003
- Version
-
- Version 0StatusaffectedConstraints<11.3.5.1001
- Version 0StatusaffectedConstraints<12.2.1.2002
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Rocket Software | UniData | unaffected |
| |||||||||
| Rocket Software | UniVerse | unaffected |
|
AND
OR
- ≤ 8.2.4
- ≤ 11.3.5
- ≥ 12.0.0 · ≤ 12.2.1
Running on/with
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (1)
- https://www.rapid7.com/blog/post/2023/03/29/multiple-vulnerabilities-in-rocket-software-unirpc-server-fixed/ Third Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://www.rapid7.com/blog/post/2023/03/29/multiple-vulnerabilities-in-rocket-software-unirpc-server-fixed/ | Third Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner rapid7
Published Mar 29, 2023
Updated Feb 18, 2025
Reserved Mar 16, 2023
Link CVE-2023-28501
CISA Vulnrichment
Updated Feb 18, 2025