漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
libsignal-service-rs doesn't sanity check plaintext envelopes are not sanity-checked
Vulnerability Description
libsignal-service-rs is a Rust version of the libsignal-service-java library which implements the core functionality to communicate with Signal servers. Prior to commit 82d70f6720e762898f34ae76b0894b0297d9b2f8, plaintext content envelopes could be injected by a server or a malicious client, and may have been able to bypass the end-to-end encryption and authentication. The vulnerability is fixed per 82d70f6720e762898f34ae76b0894b0297d9b2f8. The `Metadata` struct contains an additional `was_encrypted` field, which breaks the API, but should be easily resolvable. No known workarounds are available.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:N
Vulnerability Type
认证机制不恰当
Vulnerability Title
libsignal-service-rs 注入漏洞
Vulnerability Description
libsignal-service-rs是Whisperfish开源的一个用于与 Signal 服务器通信的 libsignal 服务。 libsignal-service-rs存在注入漏洞,该漏洞源于未正确验证内容信封的加密状态,允许明文注入。
CVSS Information
N/A
Vulnerability Type
N/A