Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
fflate through 0.8.2 is vulnerable to denial of service via an infinite loop in unzipSync(). A crafted ZIP archive with a central directory entry declaring compressed_size=0xFFFFFFFF (ZIP64 sentinel) but missing the required ZIP64 extra field tag 0x0001 causes z64e() to loop indefinitely due to out-of-bounds reads returning undefined, which coerces to 0, keeping the loop condition permanently true.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/S:N/AU:Y/R:U/V:D/RE:M/U:Amber
Vulnerability Type
不可达退出条件的循环(无限循环)
Vulnerability Title
101arrowz fflate 资源管理错误漏洞
Vulnerability Description
101arrowz fflate是101arrowz个人开发者的一款前端压缩库。 101arrowz fflate存在资源管理错误漏洞,该漏洞源于unzipSync()函数中存在无限循环问题,可能导致攻击者通过特制的ZIP归档文件(其中央目录条目声明compressed_size=0xFFFFFFFF但缺少所需的ZIP64额外字段标签0x0001)导致拒绝服务。
CVSS Information
N/A
Vulnerability Type
N/A