Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An uninitialized stack read issue exists in Amazon Ion-C versions <v1.1.4 that may allow a threat actor to craft data and serialize it to Ion text in such a way that sensitive data in memory could be exposed through UTF-8 escape sequences. To mitigate this issue, users should upgrade to version v1.1.4.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Vulnerability Type
跨界内存读
Vulnerability Title
Amazon Ion C 安全漏洞
Vulnerability Description
Amazon Ion C是amazon-ion开源的一个Amazon Ion的C语言实现。 Amazon Ion C v1.1.4之前版本存在安全漏洞,该漏洞源于未初始化栈读取问题,可能导致UTF-8转义序列暴露内存中的敏感数据。
CVSS Information
N/A
Vulnerability Type
N/A