漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Socket versions before 2.041 for Perl have an out-of-bounds heap read
Vulnerability Description
Socket versions before 2.041 for Perl have an out-of-bounds heap read.
In Socket.xs, pack_ip_mreq_source() checks the length of its source argument before the argument is read, so the check tests the byte length carried over from the preceding multiaddr argument instead. Both addresses occupy a 4-byte field, so a valid multiaddr lets a source of any length pass the check, and the source is then copied into the 4-byte imr_sourceaddr field with a fixed-size copy. A source shorter than 4 bytes is not rejected, and the copy reads up to 3 bytes past the end of its buffer.
Calling pack_ip_mreq_source() with a source value shorter than 4 bytes copies adjacent heap memory into the returned packed structure.
CVSS Information
N/A
Vulnerability Type
跨界内存读
Vulnerability Title
PEVANS Socket 缓冲区错误漏洞
Vulnerability Description
PEVANS Socket是PEVANS个人开发者的一个消息队列中间件。 PEVANS Socket 2.041之前版本存在缓冲区错误漏洞,该漏洞源于对pack_ip_mreq_source()函数中source参数的长度检查错误,导致越界堆读取。
CVSS Information
N/A
Vulnerability Type
N/A