漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
N/A
Vulnerability Description
Passing an effectively empty string to the `,ccs=` syntax extension of the mode argument in the `fopen` function in the GNU C Library version 2.45 or earlier may result in a heap buffer overflow when the mode string input to the function is attacker controlled.
This usage pattern is not seen in applications in common GNU/Linux distributions and applications that process user-supplied values for `ccs` should not pass them through without validation.
CVSS Information
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
Vulnerability Type
N/A
Vulnerability Title
GNU C Library 缓冲区错误漏洞
Vulnerability Description
GNU C Library是美国GNU基金会的一个实现C语言标准库功能的运行库。 GNU C Library 2.45及之前版本存在缓冲区错误漏洞,该漏洞源于向`fopen`函数的mode参数中的`,ccs=`语法扩展传递有效空字符串,可能导致堆缓冲区溢出。
CVSS Information
N/A
Vulnerability Type
N/A