apcupsd 3.14.14 及更早版本在 中的 函数存在未初始化栈内存泄露漏洞。该函数被 、 和 使用。在单字段处理路径中,如果匹配的 STATUS 行包含的空白分隔令牌少于三个, 不会执行任何赋值操作,但函数仍返回成功状态。因此,调用者会将未初始化的目标缓冲区内容输出到 HTTP 响应中,导致敏感信息泄露。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet