漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
iccDEV is vulnerable to stack-buffer-overflow in icFixXml()
Vulnerability Description
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to version 2.3.1.2, stack-based buffer overflow in icFixXml() function when processing malformed ICC profiles, allows potential arbitrary code execution through crafted NamedColor2 tags. This issue has been patched in version 2.3.1.2.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Vulnerability Type
栈缓冲区溢出
Vulnerability Title
iccDEV 缓冲区错误漏洞
Vulnerability Description
iccDEV是International Color Consortium开源的一个颜色配置代码库。 iccDEV 2.3.1.2之前版本存在缓冲区错误漏洞,该漏洞源于处理畸形ICC配置文件时icFixXml函数存在基于栈的缓冲区溢出,可能导致执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A