Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
A use-after-free flaw has been discovered in libcomps before version 0.1.10 in the way ObjMRTrees are merged. An attacker, who is able to make an application read a crafted comps XML file, may be able to crash the application or execute malicious code.
CVSS Information
N/A
Vulnerability Type
释放后使用
Vulnerability Title
libcomps 资源管理错误漏洞
Vulnerability Description
libcomps是一款使用C语言编写的yum.comps替代库。 libcomps 0.1.10之前版本中的‘comps_objmradix.c:comps_objmrtree_unite()’函数存在释放后重用漏洞。攻击者可借助特制的文件利用该漏洞造成应用程序崩溃或执行恶意代码。
CVSS Information
N/A
Vulnerability Type
N/A