漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Squid: Memory disclosure in FTP gateway
Vulnerability Description
Squid is a caching proxy for the Web. Prior to 7.6, due to an improper validation of syntactic correctness of input in the FTP gateway (src/clients/FtpGateway.cc), Squid is vulnerable to an out-of-bounds read: when a listing entry date in the TypeA or TypeB directory-listing formats is not followed by a filename, parsing was not restricted to the input buffer, so a trusted client accessing a misbehaving FTP server through Squid's gateway feature could read memory from random unrelated transactions. This issue is fixed in version 7.6.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Vulnerability Type
跨界内存读
Vulnerability Title
squid-cache Squid 缓冲区错误漏洞
Vulnerability Description
squid-cache Squid是squid-cache团队开源的一套代理及Web缓存服务器软件。 squid-cache Squid 7.6之前版本存在安全漏洞,该漏洞源于FTP网关中对输入语法正确性验证不当,容易受到越界读取攻击,导致信任的客户端通过Squid的网关功能访问不当FTP服务器时,能够从随机无关事务中读取内存。
CVSS Information
N/A
Vulnerability Type
N/A