漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Heap double-free in AWS Common Runtime aws-c-http
Vulnerability Description
Improper handling of HPACK dynamic table size updates in the AWS Common Runtime aws-c-http library might allow a remote threat actor operating a server to cause memory corruption on a connecting client application, potentially leading to arbitrary code execution, via a crafted sequence of HTTP/2 HEADERS frames. To remediate this issue, users should upgrade to aws-c-http version 0.11.0.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Vulnerability Type
双重释放
Vulnerability Title
aws-c-http 资源管理错误漏洞
Vulnerability Description
AWS aws-c-http是AWS的一个HTTP连接库组件。 AWS aws-c-http存在资源管理错误漏洞,该漏洞源于对HPACK动态表大小更新处理不当,可能导致远程威胁者通过特制的HTTP/2 HEADERS帧序列造成内存损坏,进而导致任意代码执行。
CVSS Information
N/A
Vulnerability Type
N/A