漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Apache HTTP Server: buffer overflow in mod_proxy_ajp via ajp_msg_check_header()
Vulnerability Description
Heap-based Buffer Overflow vulnerability in mod_proxy_ajp of Apache HTTP Server. If mod_proxy_ajp connects to a malicious AJP server this AJP server can send a malicious AJP message back to mod_proxy_ajp and cause it to write 4 attacker controlled bytes after the end of a heap based buffer. This issue affects Apache HTTP Server: through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.
CVSS Information
N/A
Vulnerability Type
堆缓冲区溢出
Vulnerability Title
Apache HTTP Server 安全漏洞
Vulnerability Description
Apache HTTP Server是美国阿帕奇(Apache)基金会的一款开源网页服务器。该服务器具有快速、可靠且可通过简单的API进行扩充的特点。 Apache HTTP Server 2.4.66及之前版本存在安全漏洞,该漏洞源于mod_proxy_ajp存在基于堆的缓冲区溢出,当连接到恶意AJP服务器时,该服务器可以发送恶意AJP消息导致在堆缓冲区末尾写入4个攻击者控制的字节。
CVSS Information
N/A
Vulnerability Type
N/A