漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Coq and Rocq Prover Print Assumptions Omits Unsafe Universe Checking Inlined Through Parameter Inline
Vulnerability Description
Print Assumptions does not report that a definition was produced while universe checking was disabled when that definition reaches the caller through Parameter Inline in a module type. Applying a functor inlines the body of the parameter, and the inlining drops the record that the term was built under Unset Universe Checking, so the resulting constant carries no trace of the unsafe operation. A module implementation can therefore prove False using a universe inconsistency, expose it through an inlined parameter, and have Print Assumptions report the dependent proof as closed under the global context. Because Print Assumptions is the in-process audit used to confirm that a development rests on no unexpected assumptions, a dependency built this way passes that audit while proving arbitrary propositions. The standalone checker coqchk does reject the resulting compiled file. The project records this in dev/doc/critical-bugs.md under non-fixed bugs and rates the risk as moderate when coqchk is not used.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N
Vulnerability Type
不充分的日志记录
Vulnerability Title
Rocq Prover 日志信息泄露漏洞
Vulnerability Description
Rocq Prover是Rocq Prover组织的一个形式化证明辅助软件。 Rocq Prover 8.11版本至9.2.0版本存在日志信息泄露漏洞,该漏洞源于Print Assumptions未报告通过Parameter Inline内联参数时在禁用宇宙检查下生成的定义,可能导致模块实现利用宇宙不一致证明任意命题并绕过审计。
CVSS Information
N/A
Vulnerability Type
N/A