Описание
surfio has an out-of-bounds read
Impact
Prior to version 0.0.19, surfio would not correctly validate size fields in irap files, leading to a buffer overflow . The severity rating assumes that surfio is used to parse untrused files in a networking context such as a web service.
Patches
The bug has been patched in version 0.0.19
Пакеты
Наименование
surfio
pip
Затронутые версииВерсия исправления
< 0.0.19
0.0.19
Связанные уязвимости
CVSS3: 9.8
nvd
8 дней назад
Surfio is a library for reading and writing surface files. Prior to 0.0.19, surfio does not correctly validate size fields in IRAP files, leading to a buffer overflow when untrusted files are parsed. The severity assumes surfio is used to parse untrusted files in a networking context such as a web service. This issue is fixed in version 0.0.19.