Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
libsafe 2.0-11 and earlier allows attackers to bypass protection against format string vulnerabilities via format strings that use the "'" and "I" characters, which are implemented in libc but not libsafe.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Libsafe格式化串攻击防护可绕过漏洞
Vulnerability Description
Libsafe是免费开放源代码设计用于防护缓冲溢出和格式化串攻击的程序,由Avaya Labs开发维护,运行在Linux系统下。 Libsafe对部分C库格式标识不能处理,可导致格式化串攻击可绕过。 Libsafe对某些格式标识类型缺少实现,C库中的格式标识"%'n" 和 "%In"在Libsafe上不能正确处理,因此攻击者可以通过这些格式标识对格式化串漏洞进行攻击而绕过Libsafe的检查。
CVSS Information
N/A
Vulnerability Type
N/A