Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
NanaZip has DotNet Single file OOB Heap Read
Vulnerability Description
NanaZip is an open source file archive Starting in version 5.0.1252.0 and prior to version 6.0.1630.0, NanaZip has an out-of-bounds heap read in `.NET Single File` bundle header parser due to missing bounds check. Opening a crafted file with NanaZip causes a crash or leaks heap data to the user. Version 6.0.1630.0 patches the issue.
CVSS Information
N/A
Vulnerability Type
缓冲区上溢读取
Vulnerability Title
NanaZip 安全漏洞
Vulnerability Description
NanaZip是M2-Team开源的一个压缩软件。 NanaZip 6.0.1630.0之前版本存在安全漏洞,该漏洞源于.NET Single File捆绑包头解析器缺少边界检查,可能导致越界堆读取。
CVSS Information
N/A
Vulnerability Type
N/A