Perl 的 Imager 模块在 1.037 版本之前存在堆缓冲区溢出漏洞,该漏洞发生在 函数中从调色板图像获取浮点采样数据时。 对于调色板图像,当 函数以 "float" 类型调用时,会为每个像素分配一个样本大小的缓冲区,并将请求的每个通道的数据写入该缓冲区。如果请求超过一个通道,就会导致写入超出缓冲区末尾的内存区域。 攻击者可以通过其提供的图像中的调色板来控制溢出的字节内容,从而可能利用此漏洞执行恶意代码或造成其他安全影响。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | - | 0 ~ 1.037 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet