PDFio 版本在 1.6.5 之前存在一个悬空指针漏洞,该漏洞位于用于字典字符串格式化的函数中。该函数将指向栈上局部缓冲区的指针存储到文档字典中,而没有复制字符串值本身。在多线程或请求池化的环境中,攻击者或并发用户可能触发栈内存在不同请求间的复用,从而导致跨租户的文档内容被损坏——即一个调用者的字典字符串值会被另一个调用者的数据静默覆盖。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| michaelrsweet | pdfio | < 1.6.5 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| michaelrsweet | pdfio | 0 ~ 1.6.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet