漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
AIS-catcher Integer Underflow in MQTT Packet Parsing leading to Heap Buffer Overflow
Vulnerability Description
AIS-catcher is a multi-platform AIS receiver. Prior to version 0.64, an integer underflow vulnerability exists in the MQTT parsing logic of AIS-catcher. This vulnerability allows an attacker to trigger a massive Heap Buffer Overflow by sending a malformed MQTT packet with a manipulated Topic Length field. This leads to an immediate Denial of Service (DoS) and, when used as a library, severe Memory Corruption that can be leveraged for Remote Code Execution (RCE). This issue has been patched in version 0.64.
CVSS Information
N/A
Vulnerability Type
堆缓冲区溢出
Vulnerability Title
AIS-catcher 数字错误漏洞
Vulnerability Description
AIS-catcher是Jasper个人开发者的一个AIS接收器。 AIS-catcher 0.64之前版本存在数字错误漏洞,该漏洞源于MQTT解析逻辑存在整数下溢,可能导致拒绝服务和内存损坏。
CVSS Information
N/A
Vulnerability Type
N/A