TGTGInsighttelegram intelligenceLIVE / telegram public index
← OnePlus OS Update Tracker

TGINSIGHT SIMILAR POSTS

查找相似内容

Source channel @OnePlusOTA · Post #310 · 9月29日

OnePlus 8T Oxygen OS 11.0.10.10.KB05BA System • Newly adapted OnePlus Buds Pro and brought new powerful features • Newly added the screenshot feature for AOD • Fixed the failed issue of Navigation gestures in some scenes • Improved system stability and fixed known issues • Updated Android security patch to 2021.08 Camera • Optimized the portrait mode effect of the front camera Ambient Display • Newly added Bitmoji AOD, co-designed with Snapchat, which will liven up the ambient display with your personal Bitmoji avatar. Your avatar will update throughout the day based on your activity and things happening around you ( Path: Settings - Customization - Clock on ambient display - Bitmoji ) MD5 Full: 5e5e05c41bdec735195e026fbd89ea46 Size Full: 2.76 GB (2966856115) Downloads Oxygen OS Server 1: Full Oxygen OS Server 2: Full Color OS Global Server 1: Full Color OS Global Server 2: Full Exported by MlgmXyysd Color OTA Bot@OnePlusOTA #Oxygen#kebab#Europe#Full

Results

找到 1 条相似帖子

搜索 #zipfile

当前筛选 #zipfile清除筛选
AIGC

@aigcrubbish · Post #6 · 2024/08/23 06:57

CPython zipfile 模块高危漏洞 CVE-2024-8088 CPython 的 zipfile 模块存在一个高危漏洞,编号为 CVE-2024-8088。该漏洞会导致在处理恶意构造的 zip 档案时,程序陷入无限循环。具体来说,当使用 zipfile.Path 类及其方法(如 namelist()`、`iterdir()`、`extractall() 等)遍历 zip 档案条目名称时,可能会触发无限循环。 此漏洞的根本原因在于 zipfile._path._ancestry() 方法中的路径处理不当。具体来说,代码中的 path.rstrip(posixpath.sep) 和 while 循环条件未正确处理路径,导致无限循环。例如,`posixpath.split("//") 返回 ("//", ""),而 "//" != posixpath.sep` 导致循环无法退出。 该漏洞已被修复,建议更新 CPython 并加强输入验证,以防止潜在的拒绝服务攻击。 原文链接:https://www.openwall.com/lists/oss-security/2024/08/22/1https://www.openwall.com/lists/oss-security/2024/08/22/4 标签:#CPython#漏洞#zipfile#无限循环 #AIGC