关键漏洞信息 漏洞标题: Heap Out-of-Bounds Read in GSSAPI Error Handling 漏洞类型: Bug 优先级: Major - P3 影响版本: None 修复版本: 2.4.2, 1.17.7 状态: Closed 描述 The and functions read one byte past the end of GSS library buffers by copying length+1 bytes from buffers that only contain length bytes. This could cause a crash (e.g. DoS) if the GSS library returns buffers allocated at page boundaries, as the driver reads one byte past the buffer end. 复现步骤 相关链接 相关问题: GODRIVER-3772 Add AddressSanitizer support for GSSAPI 关键日期 创建日期: 2022-01-20 更新日期: 2022-02-10 解决日期: 2022-01-21