Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Twisted: Denial of Service (DoS) in twisted.names via Crafted DNS Compression Pointer Chains
Vulnerability Description
Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to 26.4.0rc2, the twisted.names module is vulnerable to a Denial of Service (DoS) attack via resource exhaustion during DNS name decompression. A remote, unauthenticated attacker can exploit this by sending a crafted TCP DNS packet containing deeply chained compression pointers. This flaw bypasses previous loop-prevention logic, causing the single-threaded Twisted reactor to hang while processing millions of recursive lookups, effectively freezing the server. This vulnerability is fixed in 26.4.0rc2.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Vulnerability Type
未加控制的资源消耗(资源穷尽)
Vulnerability Title
Twisted 资源管理错误漏洞
Vulnerability Description
Twisted是Twisted Matrix Labs开源的一款使用Python语言编写的事件驱动的开源网络引擎。 Twisted 26.4.0rc2之前版本存在资源管理错误漏洞,该漏洞源于twisted.names模块在DNS名称解压缩期间存在资源耗尽问题,可能导致远程未认证攻击者通过发送特制TCP DNS数据包造成拒绝服务。
CVSS Information
N/A
Vulnerability Type
N/A