发布时间: 2025年9月5日
修改时间: 2025年9月12日
XMP Toolkit versions 2023.12 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
NVD | openEuler | |
---|---|---|
Confidentiality | High | |
Attack Vector | Local | |
CVSS评分 | N/A | 5.5 |
Attack Complexity | Low | |
Privileges Required | None | |
Scope | Unchanged | |
Integrity | None | |
User Interaction | Required | |
Availability | None |
公告名 | 概要 | 发布时间 |
---|---|---|
KylinSec-SA-2025-2876 | exempi security update | 2025年9月15日 |
产品 | 包 | 状态 |
---|---|---|
KY3.4-5A | exempi | Fixed |
V6 | exempi | Fixed |
KY3.5.3 | exempi | Fixed |
KY3.5.2 | exempi | Fixed |