Unidata netcdf-c 库(版本至 4.10.1)中存在一个越界写入(Out-of-Bounds Write)漏洞,位于 函数中。该函数在将 HDF5 属性名称复制到固定的 256 字节缓冲区时,未进行长度校验。攻击者可以构造包含超长属性名称的 HDF5 文件,以覆盖目标缓冲区,从而引发内存损坏;当应用程序枚举属性名称时,可能会导致程序崩溃。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet