脆弱性情報
高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。
脆弱性タイトル
Libsoup: libsoup: denial of service via use-after-free in http/2 server
脆弱性説明
A flaw was found in libsoup, a library for handling HTTP requests. This vulnerability, known as a Use-After-Free, occurs in the HTTP/2 server implementation. A remote attacker can exploit this by sending specially crafted HTTP/2 requests that cause authentication failures. This can lead to the application attempting to access memory that has already been freed, potentially causing application instability or crashes, resulting in a Denial of Service (DoS).
CVSS情報
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
脆弱性タイプ
释放后使用
脆弱性タイトル
libsoup 安全漏洞
脆弱性説明
libsoup是GNOME项目的一款GNOME的HTTP客户端/服务器库。 libsoup存在安全漏洞,该漏洞源于HTTP/2服务器实现中存在释放后重用漏洞,可能导致远程攻击者通过发送特制的HTTP/2请求导致身份验证失败,从而引发拒绝服务。
CVSS情報
N/A
脆弱性タイプ
N/A