漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
allegro Hostname Allocation assets.py AssetLastHostname.increment_hostname race condition
Vulnerability Description
A vulnerability was determined in allegro up to bcf65b994ef29fb3fc2e10b660e6288723d5209e. This impacts the function AssetLastHostname.increment_hostname of the file src/ralph/assets/models/assets.py of the component Hostname Allocation Handler. Executing a manipulation of the argument counter can lead to race condition. Attacks of this nature are highly complex. The exploitability is said to be difficult. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.
CVSS Information
CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
Vulnerability Type
使用共享资源的并发执行不恰当同步问题(竞争条件)
Vulnerability Title
allegro 竞争条件问题漏洞
Vulnerability Description
allegro是Allegro公司的一个主要针对视频游戏和多媒体编程的跨平台库。 allegro bcf65b994ef29fb3fc2e10b660e6288723d5209e版本存在竞争条件问题漏洞,该漏洞源于Hostname Allocation Handler组件中文件src/ralph/assets/models/assets.py的函数AssetLastHostname.increment_hostname存在竞争条件问题,通过参数counter的操作可能导致攻击。
CVSS Information
N/A
Vulnerability Type
N/A