Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
MessagePack: Out-of-bounds read/crash on Unpacker reuse after caught error
Vulnerability Description
MessagePack is the serializer implementation for Python msgpack.org. Prior to 1.2.1, there is an Out-of-bounds read/crash on Unpacker reuse after a caught error, potentially leading to a DoS attack. If the Unpacker is used repeatedly after an error occurs, the process may crash with a SEGV. This issue has been fixed in version 1.2.1.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Vulnerability Type
释放后使用
Vulnerability Title
MessagePack 资源管理错误漏洞
Vulnerability Description
MessagePack是MessagePack组织开源的一个消息序列化格式。 MessagePack 1.2.1之前版本存在资源管理错误漏洞,该漏洞源于错误处理后重用Unpacker导致越界读取,可能导致拒绝服务攻击。
CVSS Information
N/A
Vulnerability Type
N/A