ESP32-audioI2S 版本 3.4.4 至 4.0.0 存在一个基于堆的越界读取漏洞。该漏洞位于 函数中,根源在于处理 ID3 同步歌词(Synchronized Lyrics)时,长度参数被遮蔽(shadowed length parameter)。攻击者可以通过构造带有超大帧大小声明的恶意 MP3 文件或 HTTP 音频流,使读取操作越过已分配缓冲区的边界,从而导致设备崩溃或泄露相邻的堆内存。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| schreibfaul1 | ESP32-audioI2S | 3.4.4 ~ 4.0.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet