漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
N/A
Vulnerability Description
Tencent GameLoop before 4.1.21.90 downloaded updates over an insecure HTTP connection. A malicious attacker in an MITM position could spoof the contents of an XML document describing an update package, replacing a download URL with one pointing to an arbitrary Windows executable. Because the only integrity check would be a comparison of the downloaded file's MD5 checksum to the one contained within the XML document, the downloaded executable would then be executed on the victim's machine.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Tencent GameLoop 安全漏洞
Vulnerability Description
Tencent GameLoop是中国腾讯(Tencent)公司的一款安卓模拟器。能够让玩家在电脑上玩安卓游戏。 腾讯GameLoop在4.1.21.90之前存在安全漏洞,该漏洞源于处于MITM位置的恶意攻击者可利用该漏洞可以欺骗描述更新包的XML文档的内容,将下载URL替换为指向任意Windows可执行文件的URL。
CVSS Information
N/A
Vulnerability Type
N/A