在 tnef 中发现了一个漏洞。攻击者可以通过提供一个包含未压缩富文本格式(RTF)数据的特制文件来利用此漏洞。由于应用程序在 函数中复制数据前未能正确验证输入缓冲区边界,导致读取超出已分配内存范围。该缺陷可能导致应用程序崩溃,从而引发拒绝服务(DoS)攻击,或将敏感内存内容泄露到提取的输出文件中。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | - | 0 ~ 1.4.18 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet