漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
NanaZip: Unbounded memory allocation (DoS) in NanaZip WebAssembly parser via attacker-controlled section/name length fields
Vulnerability Description
NanaZip is the 7-Zip derivative intended for the modern Windows experience. Prior to 6.5.1749.0, NanaZip's WebAssembly archive handler in NanaZip.Codecs.Archive.WebAssembly.cpp allocates buffers from attacker-controlled 32-bit section and custom-name length fields without validating them against the data present in the file. A tiny crafted module can force multi-gigabyte allocations during listing or extraction through NameSize, Information.Size, and std::string or vector allocation paths, causing memory exhaustion or process termination. This issue is fixed in version 6.5.1749.0.
CVSS Information
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Vulnerability Type
未加控制的资源消耗(资源穷尽)
Vulnerability Title
M2Team NanaZip 资源管理错误漏洞
Vulnerability Description
m2team nanazip是m2team团队开源的一个压缩软件。 M2Team NanaZip 6.5.1749.0之前版本存在资源管理错误漏洞,该漏洞源于WebAssembly存档处理器在分配缓冲区时未验证节区和自定义名称长度字段,可能导致强制分配大量内存,造成内存耗尽或进程终止。
CVSS Information
N/A
Vulnerability Type
N/A