漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
N/A
Vulnerability Description
This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Sonos One Speaker 70.3-35220. Authentication is not required to exploit this vulnerability. The specific flaw exists within the msprox endpoint. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of root. Was ZDI-CAN-19846.
CVSS Information
N/A
Vulnerability Type
跨界内存读
Vulnerability Title
Sonos One Speaker 缓冲区错误漏洞
Vulnerability Description
Sonos One Speaker是美国Sonos公司的一款智能音箱。 Sonos One Speaker 70.3-35220版本存在缓冲区错误漏洞,该漏洞源于缺乏对用户提供的数据的正确验证,这可能导致读取超出已分配缓冲区的末尾,攻击者利用该漏洞可以在root上下文中执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A