snappy-java 库版本 1.1.10.8 及之前版本在类型化的 Snappy.uncompress*Array 方法中存在一个缓冲区溢出漏洞。这些方法在分配输出数组时,会用未压缩长度除以元素大小,但却将未除的原始长度传递给底层原生代码。攻击者若能控制压缩输入,便可构造导致长度值不对齐的数据,使得写入操作越过数组边界,用攻击者控制的字节破坏堆内存。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| xerial | snappy-java | ≤ 1.1.10.8 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| xerial | snappy-java | 0 ~ 1.1.10.8 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet