在 GNU libextractor 1.15 之前版本中, 函数存在一个基于栈的缓冲区溢出漏洞。该函数会根据攻击者可控的 OLE2 流数据来分配一个变长的栈数组。攻击者可以构造恶意的 StarOffice 文档,使其在栈上分配多达 4MB 的空间,从而导致栈溢出,使任何从该文档中提取元数据的应用程序崩溃。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| GNU | libextractor | 0 ~ 1.15 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet