Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Gadu-Gadu 7.20 does not properly handle MS-DOS device names in filenames, which allows remote attackers to (1) cause a denial of service (hang) via an image filename of AUX: sent twice (hang), or (2) write to the LPT1 port via a filename of "LPT1:".
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Gadu-Gadu不正确处理MS-DOS设备名漏洞
Vulnerability Description
Gadu-Gadu是一款即时消息通讯程序。 GG允许在用户间发送图形。发送者可以指定文件名,该文件名可以是特定的设备。如果用户将图形命名为"LPT1:",就可以在接收端的lpt1端口写入图形内容;如果将图形命名为"AUX:"并发送两次,第二次发送就可以阻断负责显示、接收和发送消息的线程。
CVSS Information
N/A
Vulnerability Type
N/A