以下是对该漏洞描述的中文翻译: snappy-java 库(版本至 1.1.10.8 及之前)在 方法中存在越界写入漏洞。由于未对解压后的数据大小与目标缓冲区容量进行校验,攻击者可以构造有效的压缩数据,使其解压后的体积大于目标缓冲区的容量,从而导致写入操作超出缓冲区边界,进而引发 JVM 崩溃(进程终止)。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| xerial | snappy-java | ≤ 1.1.10.8 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| xerial | snappy-java | 0 ~ 1.1.10.8 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet