漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Summarize < 0.17.0 Disk Exhaustion via Uncapped Media Download
Vulnerability Description
Summarize before 0.17.0 contains a resource exhaustion vulnerability that allows remote attackers to cause disk exhaustion by serving media responses that bypass the enforced size limit through missing or misreported Content-Length headers, chunked transfer encoding, or failed HEAD requests. Attackers who control a podcast feed or media URL can stream an unbounded response to local storage via the temp-file download path, exhausting disk or system resources on the host running the CLI.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
Vulnerability Type
不加限制或调节的资源分配
Vulnerability Title
Summarize 安全漏洞
Vulnerability Description
Summarize是Peter Steinberger个人开发者的一款支持多来源的快速摘要工具。 Summarize 0.17.0之前版本存在安全漏洞,该漏洞源于资源耗尽,远程攻击者可通过缺少或错误报告的Content-Length标头、分块传输编码或失败的HEAD请求,使媒体响应绕过强制大小限制,导致磁盘耗尽。攻击者可通过临时文件下载路径将无界响应流式传输到本地存储,耗尽主机磁盘或系统资源。
CVSS Information
N/A
Vulnerability Type
N/A