| CNNVD-ID编号 | CNNVD-202405-4798 |
| CVE编号 | CVE-2024-36114 |
| 发布时间 | 2024-05-29 |
| 更新时间 | 2024-05-30 |
| 漏洞类型 | 其他 |
| 漏洞来源 | 暂无 |
| 危险等级 | N/A |
| 威胁类型 | N/A |
| 厂 商 | airlift |
Aircompressor是airlift开源的一个将 Snappy、LZO、LZ4 和 Zstandard 压缩算法移植到 Java 的库。 Aircompressor 0.27之前版本存在安全漏洞,该漏洞源于解压器可能会使JVM崩溃并泄漏内存内容。
来源:github.com
链接:https://github.com/airlift/aircompressor/security/advisories/GHSA-973x-65j7-xcf4
来源:github.com
链接:https://github.com/airlift/aircompressor/commit/15e68df9eb0c2bfde7f796231ee7cd1982965071
来源:github.com
链接:https://github.com/airlift/aircompressor/commit/2cea90a45534f9aacbb77426fb64e975504dee6e
来源:github.com
链接:https://github.com/airlift/aircompressor/commit/cf66151541edb062ea88b6f3baab3f95e48b7b7f
来源:github.com
链接:https://github.com/airlift/aircompressor/commit/d01ecb779375a092d00e224abe7869cdf49ddc3e
CNNVD