parsedmarc 11.0.1 版本之前,在解压缩 gzip 和 ZIP 附件时,会执行一次无上限的读取操作,且对解压缩后的输出大小没有设置限制。由于 parsedmarc 会自动处理接收到的 DMARC 报告邮件,且无需用户交互,因此未经认证的远程攻击者可以向被监控的邮箱发送一封经过精心构造的邮件,其中包含高压缩比的附件。这将导致 parsedmarc 进程按照解压缩后的数据大小分配内存,从而耗尽可用 RAM,引发内存耗尽问题。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| domainaware | parsedmarc | 0 ~ 11.0.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet