漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Twisted: Denial of Service (DoS) in twisted.names via Crafted DNS Compression Pointer Chains
Vulnerability Description
Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to 26.4.0rc2, the twisted.names module is vulnerable to a Denial of Service (DoS) attack via resource exhaustion during DNS name decompression. A remote, unauthenticated attacker can exploit this by sending a crafted TCP DNS packet containing deeply chained compression pointers. This flaw bypasses previous loop-prevention logic, causing the single-threaded Twisted reactor to hang while processing millions of recursive lookups, effectively freezing the server. This vulnerability is fixed in 26.4.0rc2.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Vulnerability Type
未加控制的资源消耗(资源穷尽)
Vulnerability Title
Twisted 资源管理错误漏洞
Vulnerability Description
Twisted是Twisted Matrix Labs开源的一款使用Python语言编写的事件驱动的开源网络引擎。 Twisted 26.4.0rc2之前版本存在资源管理错误漏洞,该漏洞源于twisted.names模块在DNS名称解压缩期间存在资源耗尽问题,可能导致远程未认证攻击者通过发送特制TCP DNS数据包造成拒绝服务。
CVSS Information
N/A
Vulnerability Type
N/A