Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Off-by-one error in the inflate function in Zlib.xs in Compress::Raw::Zlib Perl module before 2.017, as used in AMaViS, SpamAssassin, and possibly other products, allows context-dependent attackers to cause a denial of service (hang or crash) via a crafted zlib compressed stream that triggers a heap-based buffer overflow, as exploited in the wild by Trojan.Downloader-71014 in June 2009.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Compress::Raw::Zlib Perl模块单字节溢出漏洞
Vulnerability Description
Compress::Raw::Zlib是Perl中使用的一个模块,提供了到zlib压缩库的底层接口。 Compress::Raw::Zlib库的Zlib.xs文件中的inflate()函数存在单字节溢出漏洞,如果用户使用链接到该函数库的Perl应用程序打开了畸形zlib-stream的话,就可以触发堆溢出,导致应用程序崩溃或执行任意代码 。
CVSS Information
N/A
Vulnerability Type
N/A