Dislocker 0.7.3 及之前版本在 和 函数中存在堆越界读取漏洞,这两个函数未对 dataset 和 datum 的大小与元数据分配大小进行验证。攻击者可以构造具有夸大 dataset 或 datum 大小的 BitLocker 卷镜像,当该卷镜像被打开或挂载时,可导致 dislocker 崩溃或泄露相邻堆内存。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet