Xerial snappy-java 从 1.1.7.4 到 1.1.10.10(不含 1.1.10.10)版本在 SnappyFramedInputStream 中存在一个双重释放漏洞。当替换分配失败时,该漏洞会导致池化缓冲区被释放两次。攻击者可以构造具有超大声明块长度的帧数据,从而触发内存溢出错误(OutOfMemoryError),导致共享底层数组暴露或覆盖其他流的解压缩数据。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| xerial | snappy-java | 1.1.7.4< 1.1.10.10 |
affected |
1.1.10.10 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| xerial | snappy-java | 1.1.7.4 ~ 1.1.10.10 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet