在 1.5.7-14 之前的 zstd-jni 版本中, 构造函数未能验证 offset 和 length 参数,从而导致越界内存读取。攻击者可以通过提供不可信的 offset 或 length 值,将 native 堆内存读取到压缩字典中,通常会导致 JVM 崩溃。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet