漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
idna accepts Punycode labels that do not produce any non-ASCII when decoded
Vulnerability Description
Improper Validation of Unsafe Equivalence in punycode by the idna crate from Servo rust-url allows an attacker to create a punycode hostname that one part of a system might treat as distinct while another part of that system would treat as equivalent to another hostname.
CVSS Information
N/A
Vulnerability Type
CWE-1289
Vulnerability Title
Servo 安全漏洞
Vulnerability Description
Servo是Servo开源的一个用 Rust 语言编写的原型 Web 浏览器引擎。 Servo存在安全漏洞,该漏洞源于punycode不安全等价验证不当,可能导致主机名混淆。
CVSS Information
N/A
Vulnerability Type
N/A