漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
PDFio < 1.6.5 Dangling Pointer via Dictionary String-Formatting
Vulnerability Description
PDFio before 1.6.5 contains a dangling pointer vulnerability in the dictionary string-formatting function that stores a pointer to a stack-local buffer in the document dictionary without copying the string value. In multi-threaded or pooled-request environments, attackers or concurrent users can trigger stack memory reuse across requests, causing cross-tenant document content corruption by silently overwriting one caller's dictionary string values with another caller's data.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Vulnerability Type
无效指针解引用
Vulnerability Title
Michael R Sweet PDFio 资源管理错误漏洞
Vulnerability Description
Michael R Sweet PDFio是Michael R Sweet个人开发者的一个读写PDF文件的库。 Michael R Sweet PDFio 1.6.5之前版本存在资源管理错误漏洞,该漏洞源于字典字符串格式化函数将指向栈本地缓冲区的指针存储到文档字典而未复制字符串值,可能导致多线程或池化请求环境中攻击者或并发用户触发栈内存重用,造成跨租户文档内容被篡改。
CVSS Information
N/A
Vulnerability Type
N/A