CyberRota Analysis
AI-GeneratedApache Fory C++ versions from 0.14.0 to 1.5.0 are vulnerable to an out-of-bounds read during the deserialization of structs with tagged integer fields, which could lead to information disclosure or denial of service. Organizations utilizing affected versions should prioritize upgrading to Apache Fory 1.5.0 to mitigate these risks, especially if their applications involve tagged integer fields. Those not using Apache Fory C++ or tagged integer fields are not impacted by this vulnerability.
Original NVD Description
Out-of-bounds Read vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0 when deserializing structs containing tagged integer fields. A crafted input payload may trigger an out-of-bounds heap read in the tagged integer fast-path deserializer, potentially causing information disclosure or denial of service. Users are recommended to upgrade to Apache Fory 1.5.0, which fixes this issue. Applications that do not use Apache Fory C++ or do not use tagged integer fields are not affected.
Related CVEs
Other vulnerabilities affecting the same vendor(s)