漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Libsoup: libsoup: http header injection or response splitting via crlf injection in content-disposition header
Vulnerability Description
A flaw was found in libsoup. An attacker who can control the input for the Content-Disposition header can inject CRLF (Carriage Return Line Feed) sequences into the header value. These sequences are then interpreted verbatim when the HTTP request or response is constructed, allowing arbitrary HTTP headers to be injected. This vulnerability can lead to HTTP header injection or HTTP response splitting without requiring authentication or user interaction.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
Vulnerability Type
对CRLF序列的转义处理不恰当(CRLF注入)
Vulnerability Title
libsoup 注入漏洞
Vulnerability Description
libsoup是GNOME项目的一款GNOME的HTTP客户端/服务器库。 libsoup存在注入漏洞,该漏洞源于Content-Disposition标头输入控制不当,可能导致HTTP标头注入或HTTP响应拆分。
CVSS Information
N/A
Vulnerability Type
N/A