漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
sslh Packet Dumping probe.c hexdump format string
Vulnerability Description
A vulnerability, which was classified as critical, has been found in sslh. This issue affects the function hexdump of the file probe.c of the component Packet Dumping Handler. The manipulation of the argument msg_info leads to format string. The attack may be initiated remotely. The name of the patch is b19f8a6046b080e4c2e28354a58556bb26040c6f. It is recommended to apply a patch to fix this issue. The identifier VDB-216497 was assigned to this vulnerability.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
Vulnerability Type
内存缓冲区边界内操作的限制不恰当
Vulnerability Title
sslh 格式化字符串错误漏洞
Vulnerability Description
sslh是Yves Rutschle个人开发者的一个应用协议多路复用器。 sslh存在格式化字符串错误漏洞,该漏洞源于其Packet Dumping Handler组件的hexdump函数的参数msg_info的操作导致格式化字符串。
CVSS Information
N/A
Vulnerability Type
N/A