zstd-jni 版本 1.5.5-6 至 1.5.7-13 存在一个越界读取漏洞,位于 函数中,该函数未对负数的 参数进行有效校验。攻击者可以传入负的偏移值,从而绕过边界检查,使程序进入原生帧头解析器,导致发生越界内存读取,进而可能引发信息泄露或 JVM 崩溃。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet