Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Buffer overflow in efingerd 1.5 and earlier, and possibly up to 1.61, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a finger request from an IP address with a long hostname that is obtained via a reverse DNS lookup.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
EFingerD反向解析缓冲溢出漏洞
Vulnerability Description
EfingerD是一款免费的开放源代码的finger守护程序,使用在Linux操作系统下。 EfingerD在处理域信息中没有正确的处理,可导致缓冲溢出。 当主机连接到finger守护程序的时候,EfingerD默认从连接主机的IP地址中获取域信息并尝试进行解析,但是,如果主机名字超过100字节以上,就会发生缓冲溢出,可导致堆栈变量被覆盖,包括返回地址信息等,存在以efingerd的权利执行任意代码的可能。 问题存在于如下代码中: static char *lookup_addr (struct in_a
CVSS Information
N/A
Vulnerability Type
N/A