Gosub 浏览器引擎(gosub-engine)在 0.1.0 版本及 commit 46868b3 之前的 main 分支中存在不受控制的递归问题。攻击者可通过包含大量深度嵌套元素的 SVG 文档,导致拒绝服务(栈溢出和应用程序崩溃)。由于该引擎未对处理的 SVG 节点嵌套深度进行限制,渲染此类文档时会导致线程栈溢出,从而终止应用程序。恶意 SVG 文档可通过 IMG 元素的 SRC 属性嵌入,因此只需诱骗受害者访问攻击者控制的网页即可实现 exploit。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| gosub-io | gosub-engine | < 46868b3deae44544bee2a13e756772966dde950e |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| gosub-io | gosub-engine | 0 ~ 46868b3deae44544bee2a13e756772966dde950e | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet