zstd-jni 的 1.2.0 至 1.5.7-13 版本中,由于在 ZstdDictDecompress 构造函数中,偏移量(offset)和长度(length)参数从未针对字典数组的边界进行验证,从而存在一个越界读取漏洞。攻击者可以通过提供任意的 offset 或 length 值,使程序读取到所提供数组末尾之外的内存区域,这可能导致 JVM 终止。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet