Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Integer overflow in the _zip_readcdir function in zip_open.c in libzip 0.10 allows remote attackers to execute arbitrary code via the size and offset values for the central directory in a zip archive, which triggers "improper restrictions of operations within the bounds of a memory buffer" and an information leak.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
libzip整数溢出漏洞
Vulnerability Description
libzip是软件开发者Dieter Baron和Thomas Klausner共同研发的一个用于读取、创建和修改zip压缩包的C库。 libzip 0.10版本在处理中心目录结构的大小和偏移量时, "_zip_readcdir()"函数中存在整数溢出漏洞。攻击者可通过特制的ZIP文件,导致已分配缓冲器之外的内存引用。
CVSS Information
N/A
Vulnerability Type
N/A