脆弱性情報
高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。
脆弱性タイトル
Rsync < 3.4.3 Integer Overflow Information Disclosure
脆弱性説明
Rsync version 3.4.2 and prior contain an integer overflow vulnerability in the compressed-token decoder where a 32-bit signed counter is not checked for overflow, allowing a malicious sender to trigger an overflow that causes the receiver process to read and return data from outside the intended buffer bounds. Attackers can exploit this vulnerability to disclose process memory contents including environment variables, passwords, heap and stack data, and library memory pointers, significantly reducing ASLR effectiveness and facilitating further exploitation.
CVSS情報
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
脆弱性タイプ
整数溢出或超界折返
脆弱性タイトル
Rsync 缓冲区错误漏洞
脆弱性説明
Rsync是RsyncProject开源的一款快速且用途广泛的文件复制工具。用于远程文件和本地文件。 Rsync 3.4.2及之前版本存在缓冲区错误漏洞,该漏洞源于压缩令牌解码器中32位有符号计数器未检查溢出,可能导致接收进程读取并返回缓冲区外数据,泄露进程内存内容。
CVSS情報
N/A
脆弱性タイプ
N/A