Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Off-by-one error in the read_token_word function in parse.y in GNU Bash through 4.3 bash43-026 allows remote attackers to cause a denial of service (out-of-bounds array access and application crash) or possibly have unspecified other impact via deeply nested for loops, aka the "word_lineno" issue.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
GNU Bash 缓冲区溢出漏洞
Vulnerability Description
GNU Bash是美国软件开发者布莱恩-福克斯(Brian J. Fox)为GNU计划而编写的一个Shell(命令语言解释器),它运行于类Unix操作系统中(Linux系统的默认Shell),并能够从标准输入设备或文件中读取、执行命令,同时也结合了一部分ksh和csh的特点。 GNU Bash 4.3 bash43-026及之前版本的parse.y文件中的‘read_token_word’函数中存在差一错误漏洞。远程攻击者可通过多层的嵌套循环利用该漏洞造成拒绝服务(越边界数组访问和应用程序崩溃)。
CVSS Information
N/A
Vulnerability Type
N/A