漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
mackron / dr_libs dr_flac.h Excessive Memory Allocation in PICTURE Metadata Parsing
Vulnerability Description
dr_libs dr_flac.h version 0.13.3 and earlier (fixed in commits fefced4, 4f5a4cd, and 663239a) contain an uncontrolled memory allocation vulnerability in drflac__read_and_decode_metadata() that allows attackers to trigger excessive memory allocation by supplying crafted PICTURE metadata blocks. Attackers can exploit attacker-controlled mimeLength and descriptionLength fields to cause denial of service through memory exhaustion when processing FLAC streams with metadata callbacks.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Vulnerability Type
未经控制的内存分配
Vulnerability Title
dr_libs 安全漏洞
Vulnerability Description
dr_libs是David Reid个人开发者的一个C/C++的音频解码库。 dr_libs 0.13.3及之前版本存在安全漏洞,该漏洞源于drflac__read_and_decode_metadata函数存在未受控内存分配,可能导致攻击者通过特制PICTURE元数据块触发过度内存分配,造成拒绝服务。
CVSS Information
N/A
Vulnerability Type
N/A