漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
wire-ios has Persistent Remote DoS via Integer Underflow
Vulnerability Description
wire-ios is an iOS client for the Wire secure messaging application. Prior to version 4.16.0, upon receiving a crafted malicious Proteus external message with an encrypted payload that is shorter than 16 bytes, the Wire iOS client crashes. The crash is triggered automatically after message receival with no user interaction. Since the malicious message persists in the conversation, the app enters a crash loop on relaunch and cannot be reopened until the local state is wiped. This issue has been fixed with version 4.16.0 which introduces the missing length check and is available via the App Store. No known workarounds are available.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Vulnerability Type
输入验证不恰当
Vulnerability Title
Wire-ios 数字错误漏洞
Vulnerability Description
Wire-ios是一个处理移动应用程序中显示的所有数据的客户端层。 wire-ios 4.16.0之前版本存在数字错误漏洞,该漏洞源于缺少长度检查,可能导致在接收特制恶意Proteus外部消息时崩溃。
CVSS Information
N/A
Vulnerability Type
N/A