漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
漏洞
N/A
漏洞信息
An IMAP FETCH response line indicates the size of the returned data, in number of bytes. When that response says the data is zero bytes, libcurl would pass on that (non-existing) data with a pointer and the size (zero) to the deliver-data function. libcurl's deliver-data function treats zero as a magic number and invokes strlen() on the data to figure out the length. The strlen() is called on a heap based buffer that might not be zero terminated so libcurl might read beyond the end of it into whatever memory lies after (or just crash) and then deliver that to the application as if it was actually downloaded.
漏洞信息
N/A
漏洞
N/A
漏洞
Haxx curl和libcurl 缓冲区错误漏洞
漏洞信息
cURL/libcURL 7.20.0版本至7.56.0版本中存在缓冲区溢出漏洞,该漏洞源于程序没有充分的对用户提交的数据执行边界检测,导致复制数据的大小超过了缓冲区的空间。攻击者可利用该漏洞获取敏感信息或造成拒绝服务。
漏洞信息
N/A
漏洞
N/A