Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Buffer overflow in net_swapscore for typespeed 0.4.1 and earlier allows remote attackers to execute arbitrary code.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Typespeed远程内存破坏漏洞
Vulnerability Description
Typespeed是一款可远程使用的打字游戏服务程序。 Typespeed中的net_swapscore()函数对用户提交数据缺少充分检查,远程攻击者可以利用这个漏洞进行缓冲区溢出攻击,可能以服务程序进程权限执行任意指令。 问题是net_swapscore()函数中在执行'strncpy'调用前没有进行正确的缓冲区边界检查,提交超长数据给此函数可触发缓冲区溢出,精心构建提交数据可能以服务程序进程权限执行任意指令。
CVSS Information
N/A
Vulnerability Type
N/A