漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
GNU Wget 1.25.0 Heap Buffer Overflow via HTML Attribute Encoding
Vulnerability Description
GNU Wget through 1.25.0, fixed in commit dd692d9, contains a heap buffer overflow vulnerability in the html_quote_string() function in src/convert.c that allows a remote attacker to trigger memory corruption by supplying a crafted HTML attribute with a large number of characters requiring entity encoding. A server-supplied HTML attribute causes a signed integer counter to overflow during output size accumulation, resulting in an undersized heap allocation and subsequent heap buffer overflow during the copy phase.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:H
Vulnerability Type
整数溢出或超界折返
Vulnerability Title
GNU wget 数字错误漏洞
Vulnerability Description
GNU wget是美国GNU基金会开源的一个文件下载工具。 GNU wget 1.25.0及之前版本存在数字错误漏洞,该漏洞源于html_quote_string函数中堆缓冲区溢出,允许远程攻击者通过提供特制的HTML属性触发内存损坏,导致整数溢出和后续的堆缓冲区溢出。
CVSS Information
N/A
Vulnerability Type
N/A