Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
yaSSL 1.7.5 and earlier, as used in MySQL and possibly other products, allows remote attackers to cause a denial of service (crash) via a Hello packet containing a large size value, which triggers a buffer over-read in the HASHwithTransform::Update function in hash.cpp.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
yaSSL 'hash.cpp' 多个缓存溢出漏洞
Vulnerability Description
yaSSL是用于实现SSL的开源软件包。 yaSSL 1.7.5和早期的版本,使用的MySQL和其他产品,允许远程攻击者通过发送一个包含超长超大值的Hello数据包引起一次拒绝服务攻击,这是由于hash.cpp中的HASHwithTransform::Update函数的一个读操作缓冲溢出引发的。
CVSS Information
N/A
Vulnerability Type
N/A