Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Integer underflow in crypto_sign_open() leads to buffer overflow
Vulnerability Description
CROSS implementation contains reference and optimized implementations of the CROSS post-quantum signature algorithm. Prior to commit fc6b7e7, there is a buffer overflow in crypto_sign_open() caused by an underflow of the integer mlen. This issue has been patched via commit fc6b7e7.
CVSS Information
N/A
Vulnerability Type
栈缓冲区溢出
Vulnerability Title
CROSS-implementation 安全漏洞
Vulnerability Description
CROSS-implementation是CROSS Signature team开源的一个非对称签名算法的C语言实现库。 CROSS-implementation存在安全漏洞,该漏洞源于crypto_sign_open()函数中整数mlen下溢,可能导致缓冲区溢出。
CVSS Information
N/A
Vulnerability Type
N/A