Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

资源未释放:文件 #39

Open
QiAnXinCodeSafe opened this issue Nov 5, 2018 · 2 comments
Open

资源未释放:文件 #39

QiAnXinCodeSafe opened this issue Nov 5, 2018 · 2 comments

Comments

@QiAnXinCodeSafe
Copy link

QiAnXinCodeSafe commented Nov 5, 2018

您好,我是奇虎360代码卫士团队的工作人员,在我们的开源项目检测中发现roncoo-pay存在资源未释放:文件漏洞,详细信息如下:
image
在FileUtils.java中第143行,zip在创建使用后并未进行合理释放,将会降低系统性能,攻击者还有可能会通过耗尽资源池的方式发起拒绝服务攻击。建议在finally代码块中手动释放文件资源。

@tintummawgyi
Copy link

မသိခဲ့လို႔ မွားသြားခဲ့မိတာပါ

@piaoyaoi
Copy link

在?v个岗位

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants