漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Buffa: Use-After-Free in OwnedView via Unsound 'static Lifetime Promotion in Deref
Vulnerability Description
Buffa is a pure-Rust Protocol Buffers implementation with first-class protobuf editions support. Prior to 0.7.0, a soundness bug in the OwnedView<V> type allowed safe Rust code to trigger a use-after-free: the OwnedView::decode constructor transmuted a borrowed slice to &'static [u8], and the Deref implementation exposed the promoted 'static lifetime on borrowed view fields (such as &'static str and &'static [u8]) to callers, so the borrow checker permitted those references to outlive the OwnedView; once the OwnedView was dropped and its backing buffer freed, the references became dangling, enabling memory corruption, information disclosure of freed heap contents, and cross-thread misuse without any unsafe code in the calling application. This issue is fixed in version 0.7.0.
CVSS Information
CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N
Vulnerability Type
信息暴露
Vulnerability Title
Anthropic buffa 信息泄露漏洞
Vulnerability Description
Anthropic buffa是美国Anthropic公司的一款代理服务器软件。 Anthropic buffa 0.7.0之前版本存在安全漏洞,该漏洞源于OwnedView<V>类型中的健全性错误,允许安全Rust代码触发释放后重用。
CVSS Information
N/A
Vulnerability Type
N/A