Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Array index error in the uri_lookup function in the URI parser for neon 0.26.0 to 0.26.2, possibly only on 64-bit platforms, allows remote malicious servers to cause a denial of service (crash) via a URI with non-ASCII characters, which triggers a buffer under-read due to a type conversion error that generates a negative index.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Neon LibNeon Non-Ascii Character URI Data uri_lookup函数拒绝服务漏洞
Vulnerability Description
64-bit平台上的neon 0.26.0到0.26.2版本的URI解析器中的uri_lookup函数存在数组索引错误。远程恶意服务商可以借助一个带有非ASCII字符的URI,来引起拒绝服务攻击(崩溃)。由负指针生成的类别转换错误会触发一个缓冲区under-read。
CVSS Information
N/A
Vulnerability Type
N/A