漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
wrong reuse of SMB connection
Vulnerability Description
libcurl might in some circumstances reuse the wrong connection for SMB(S)
transfers.
libcurl features a pool of recent connections so that subsequent requests can
reuse an existing connection to avoid overhead.
When reusing a connection a range of criteria must be met. Due to a logical
error in the code, a network transfer operation that was requested by an
application could wrongfully reuse an existing SMB connection to the same
server that was using a different "share" than the new subsequent transfer
should.
This could in unlucky situations lead to the download of the wrong file or the
upload of a file to the wrong place. When this happens, the same credentials
are used and the server name is the same.
CVSS Information
N/A
Vulnerability Type
对错误会话暴露数据元素
Vulnerability Title
libcurl 代码问题漏洞
Vulnerability Description
libcurl是cURL开源的一个免费且易于使用的客户端 URL 传输库。 libcurl存在代码问题漏洞,该漏洞源于连接重用逻辑错误,可能导致SMB传输错误地重用使用不同共享的现有连接,从而导致下载或上传错误文件。
CVSS Information
N/A
Vulnerability Type
N/A