漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
YAML::Syck versions through 1.36 for Perl has several potential security vulnerabilities including a high-severity heap buffer overflow in the YAML emitter
Vulnerability Description
YAML::Syck versions through 1.36 for Perl has several potential security vulnerabilities including a high-severity heap buffer overflow in the YAML emitter.
The heap overflow occurs when class names exceed the initial 512-byte allocation.
The base64 decoder could read past the buffer end on trailing newlines.
strtok mutated n->type_id in place, corrupting shared node data.
A memory leak occurred in syck_hdlr_add_anchor when a node already had an anchor. The incoming anchor string 'a' was leaked on early return.
CVSS Information
N/A
Vulnerability Type
堆缓冲区溢出
Vulnerability Title
YAML::Syck 安全漏洞
Vulnerability Description
YAML::Syck是CPAN Authors开源的一个Perl库。 YAML::Syck 1.36及之前版本存在安全漏洞,该漏洞源于YAML发射器中存在堆缓冲区溢出等问题,可能导致内存损坏或信息泄露。
CVSS Information
N/A
Vulnerability Type
N/A