pocoproject.poco is vulnerable to Integer Overflow
61
Medium Risk
Affected versions of this package are vulnerable to an integer overflow in UTF-32 encoding methods, where processing a UTF-32 byte sequence with a value ≥ 0x80000000 returns a negative integer due to improper handling of signed integers. An attacker could craft a malicious UTF-32 input that triggers this overflow, potentially leading to incorrect character processing, memory corruption, or crashes in applications relying on these functions for string conversion, possibly enabling denial of service (DoS) or other undefined behavior.
You are affected if you are using a version that falls within the vulnerable range.
pocoproject.poco is vulnerable to Integer Overflow in versions 1.11.0 - 1.11.8p1 and 1.12.0 - 1.12.5p1.
Upgrade the pocoproject.poco library to the patch version.
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant