AirSane 是一个 SANE 前端程序,同时也是一个支持 Apple AirScan 协议的扫描仪服务器。在 0.4.12 之前的版本中,AirSane 的自定义 HTTP 服务器实现存在一个漏洞,使得远程未认证的攻击者能够通过内存耗尽(OOM)触发拒绝服务(DoS)。 具体而言,在 中, 函数读取 请求头,并直接将该值传递给 ,但缺少对上限值的校验和安全的解析逻辑。攻击者可以发送一个带有异常大 值的 HTTP POST 请求,迫使守护进程尝试分配数 GB 的内存,导致 异常并立即使 AirSane 进程崩溃。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| SimulPiscator | AirSane | < 0.4.12 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| SimulPiscator | AirSane | < 0.4.12 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet