file type是Sindre Sorhus个人开发者的一个文件类型检测工具。 file type 20.0.0版本至21.3.1版本存在安全漏洞,该漏洞源于特制ZIP文件在使用fileTypeFromBuffer、fileTypeFromBlob或fileTypeFromFile进行类型检测时可能触发内存过度增长,基于流的检测强制执行ZIP解压缩输出限制,但对已知大小的输入未强制执行,可能导致小型压缩ZIP使file-type在处理基于ZIP的格式时解压缩和处理更大的有效载荷。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| sindresorhus | file-type | >= 20.0.0, < 21.3.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet