msgpack-java 0.9.12 及更早版本中存在一个整数溢出漏洞,位于 方法中,发生在处理具有大量元素计数的 MAP32 容器时。攻击者可以提供一个大于或等于 的 MAP32 元素计数,当该计数值被加倍时发生整数回绕(wrap),导致解析器游标(cursor)失去同步,使得攻击者控制的数据被错误地返回,替代了后续字段的正常内容。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| msgpack | msgpack-java | ≤ 0.9.12 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| msgpack | msgpack-java | 0 ~ 0.9.12 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet