漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
HTTP::Date versions before 6.08 for Perl allow CPU exhaustion via polynomial regex backtracking in parse_date
Vulnerability Description
HTTP::Date versions before 6.08 for Perl allow CPU exhaustion via polynomial regex backtracking in parse_date.
parse_date() matches the date string against a chain of alternative regexes, and str2time() delegates to it. Several of these patterns place unbounded quantifiers next to each other before a trailing `\s*$` anchor. A valid date prefix followed by a long interior run of digits, letters, or whitespace and a single trailing byte that defeats the final match forces the engine to repartition the run, giving polynomial (about quadratic) backtracking. A header value of a few tens of kilobytes runs for tens of seconds of CPU.
HTTP::Date parses timestamps such as HTTP `Date`, `Expires`, and `Last-Modified` headers, which commonly originate from untrusted sources. Any caller that passes an untrusted date header to str2time() or parse_date() can be driven to consume unbounded CPU, a denial of service.
CVSS Information
N/A
Vulnerability Type
CWE-1333
Vulnerability Title
OALDERS HTTP::Date 资源管理错误漏洞
Vulnerability Description
OALDERS HTTP::Date是OALDERS团队的一款日期处理工具。 OALDERS HTTP::Date 6.08之前版本存在资源管理错误漏洞,该漏洞源于parse_date函数中的正则表达式多项式回溯,可能导致CPU耗尽,造成拒绝服务。
CVSS Information
N/A
Vulnerability Type
N/A