The bzip2 crate before 0.4.4 for Rust allow attackers to cause a denial of service via a large file that triggers an integer overflow in mem.rs. NOTE: this is unrelated to the https://crates.io/crates/bzip2-rs product.
{
"nvd_published_at": "2023-01-10T01:15:00Z",
"cwe_ids": [
"CWE-190"
],
"severity": "HIGH",
"github_reviewed_at": "2023-01-10T22:10:17Z",
"github_reviewed": true
}