漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
ProxySQL pre-auth heap overflow in MySQL and PostgreSQL first-packet handling
Vulnerability Description
ProxySQL is a proxy for MySQL and its forks, as well as PostgreSQL. Versions 2.0.18 through 3.0.8 have a pre-authentication heap memory corruption vulnerability in the MySQL and PostgreSQL protocol first-read paths. A remote unauthenticated client can declare an oversized first packet length, and ProxySQL passes that attacker-controlled length directly to `recv()` while writing into a fixed 32 KB input queue. Version 3.0.9 patches the issue.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
跨界内存写
Vulnerability Title
ProxySQL 缓冲区错误漏洞
Vulnerability Description
ProxySQL ProxySQL是ProxySQL组织开源的一个面向MySQL、PostgreSQL及其生态系统的领先数据库代理,支持高性能连接管理、高可用故障转移和实时查询分析。 ProxySQL 2.0.18版本至3.0.8及之前版本存在缓冲区错误漏洞,该漏洞源于MySQL和PostgreSQL协议首次读取路径中存在预身份验证堆内存损坏问题,可能导致远程未验证攻击者声明超大的第一个数据包长度,导致堆内存损坏。
CVSS Information
N/A
Vulnerability Type
N/A