Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Directory traversal vulnerability in the GeoIP_update_database_general function in libGeoIP/GeoIPUpdate.c in GeoIP 1.4.0 allows remote malicious update servers (possibly only update.maxmind.com) to overwrite arbitrary files via a .. (dot dot) in the database filename, which is returned by a request to app/update_getfilename.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
GeoIP 'GeoIPUpdate.C' 目录遍历漏洞
Vulnerability Description
GeoIP 1.4.0版本的libGeoIP/GeoIPUpdate.c中的GeoIP_update_database_general函数存在目录遍历漏洞。远程恶意更新服务商(可能仅仅是update.maxmind.com)可以借助数据库文件名中的..,重写任意文件。对app/update_getfilename的请求会返回该漏洞。
CVSS Information
N/A
Vulnerability Type
N/A