漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Apache Fory: Heap type confusion and out-of-bounds read/write in C++ compatible-mode field-skip paths
Vulnerability Description
Heap type confusion and out-of-bounds read/write in the Apache Fory C++ implementation. When deserializing data in compatible mode, the field-skip paths do not correctly validate the declared field types against the actual data, so input with an inconsistent schema can cause type confusion and out-of-bounds memory access. Only the C++ implementation is affected; other language implementations of Apache Fory are not. This issue affects Apache Fory C++: from 0.14.0 before 1.4.0. Users are recommended to upgrade to version 1.4.0, which fixes the issue.
CVSS Information
N/A
Vulnerability Type
使用不兼容类型访问资源(类型混淆)
Vulnerability Title
Apache Fory C++ 反序列化注入漏洞
Vulnerability Description
Apache Fory C++是美国Apache基金会的一款开发框架。 Apache Fory C++ 0.14.0版本至1.4.0之前版本存在安全漏洞,该漏洞源于在兼容模式下反序列化数据时,field-skip路径未正确验证声明的字段类型与实际数据,导致类型混淆和越界内存访问。
CVSS Information
N/A
Vulnerability Type
N/A