目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2023-28638— Snappier 缓冲区错误漏洞

一分钟漏洞结论

影响对象
brantburnett Snappier
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

Snappier是Brant Burnett个人开发者的一个Google Snappy压缩算法的纯C#端口。 Snappier 1.1.0版本存在缓冲区错误漏洞。攻击者利用该漏洞导致缓冲区溢出,从而进程终止。

CVSS 7.0 · High EPSS 0.55% · P44
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2023-28638 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
Stack references to locations outside buffers may become invalid if they exist during a GC compaction in Snappier
来源: CVE Program / CVE List V5
Vulnerability Description
Snappier is a high performance C# implementation of the Snappy compression algorithm. This is a buffer overrun vulnerability that can affect any user of Snappier 1.1.0. In this release, much of the code was rewritten to use byte references rather than pointers to pinned buffers. This change generally improves performance and reduces workload on the garbage collector. However, when the garbage collector performs compaction and rearranges memory, it must update any byte references on the stack to refer to the updated location. The .NET garbage collector can only update these byte references if they still point within the buffer or to a point one byte past the end of the buffer. If they point outside this area, the buffer itself may be moved while the byte reference stays the same. There are several places in 1.1.0 where byte references very briefly point outside the valid areas of buffers. These are at locations in the code being used for buffer range checks. While the invalid references are never dereferenced directly, if a GC compaction were to occur during the brief window when they are on the stack then it could invalidate the buffer range check and allow other operations to overrun the buffer. This should be very difficult for an attacker to trigger intentionally. It would require a repetitive bulk attack with the hope that a GC compaction would occur at precisely the right moment during one of the requests. However, one of the range checks with this problem is a check based on input data in the decompression buffer, meaning malformed input data could be used to increase the chance of success. Note that any resulting buffer overrun is likely to cause access to protected memory, which will then cause an exception and the process to be terminated. Therefore, the most likely result of an attack is a denial of service. This issue has been patched in release 1.1.1. Users are advised to upgrade. Users unable to upgrade may pin buffers to a fixed location before using them for compression or decompression to mitigate some, but not all, of these cases. At least one temporary decompression buffer is internal to the library and never pinned.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H
来源: CVE Program / CVE List V5
Vulnerability Type
内存缓冲区边界内操作的限制不恰当
来源: CVE Program / CVE List V5
Vulnerability Title
Snappier 缓冲区错误漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
Snappier是Brant Burnett个人开发者的一个Google Snappy压缩算法的纯C#端口。 Snappier 1.1.0版本存在缓冲区错误漏洞。攻击者利用该漏洞导致缓冲区溢出,从而进程终止。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

受影响产品

厂商 产品 影响版本 CPE 订阅
brantburnett Snappier = 1.1.0 -

二、漏洞 CVE-2023-28638 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2023-28638 的情报信息

请登录查看更多情报信息。

CVE-2023-28638 补丁与修复 (1)

CVE-2023-28638 厂商安全公告 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2023-28638

暂无评论


发表评论