MKVToolNix 版本 101.0 及之前版本中,其捆绑的 avilib 库的 ODML superindex 解析器中存在堆缓冲区溢出漏洞。该漏洞源于 32 位算术运算中的整数回绕(integer wraparound)。攻击者可以构造一个恶意的 AVI 文件,其中包含过大的条目计数,导致堆内存分配尺寸过小,从而在使用 mkvmerge 解析该文件时触发堆缓冲区溢出。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Moritz Bunkus | MKVToolNix | ≤ 101.0 |
affected |
1495126138e086080f0163bee27fafbdf956a1d0 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Moritz Bunkus | MKVToolNix | 0 ~ 101.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet