Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Buffer overflow in the netlog function in pen.c for Pen 0.9.1 and 0.9.2 allows remote attackers to execute arbitrary commands via malformed log messages.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Pen netlogging远程缓冲区溢出漏洞
Vulnerability Description
Pen是软件开发者Ulric Eriksson所研发的一套基于TCP协议的负载平衡工具。该工具支持把日志信息记录在远程服务器上。 Pen中的netlog()函数对数据缺少正确处理,远程攻击者可以利用这个漏洞进行缓冲区溢出攻击。 Pen中的netlog()函数存在缓冲区溢出问题,远程攻击者可以操作包含在日志信息中的数据而使netlog()崩溃,可能以Pen进程的权限在系统中执行任意指令。
CVSS Information
N/A
Vulnerability Type
N/A