CNNVD-202601-1783 Information
Jan 10, 2026
cve
CNNVD ID
CNNVD-202601-1783
Related CVE
- CNNVD Published: 2026-01-10
Description (Chinese)
CryptoLib是NASA开源的一个应用程序。用于使用 CCSDS 空间数据链路安全协议提供纯软件解决方案。 CryptoLib 1.4.3之前版本存在缓冲区错误漏洞,该漏洞源于base64urlDecode函数在检查前解引用输入,可能导致越界读取或进程崩溃。
Description (English)
Criptolib is an application from NASA open source. Provides pure software solutions using CCDS spatial data link security protocols. The previous version of CriptoLib 1.4.3 had an error loophole in the buffer zone, which stemmed from the fact that the Base64urlDecode function unquoted input before checking, which could lead to cross-border reading or process collapse.
Hazard Level
High
Vulnerability Type
缓冲区错误
Affected Vendor
美国国家航空航天局
Published
2026-01-10
Last Modified
2026-02-24
References
https://github.com/nasa/CryptoLib/releases/tag/v1.4.3 https://github.com/nasa/CryptoLib/security/advisories/GHSA-wc29-5hw7-mpj8
Patch
https://github.com/nasa/CryptoLib/releases
Share on: