Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Malcolm has Uncontrolled Resource Consumption in Archive Extraction (Inode-Exhaustion DoS)
Vulnerability Description
Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, `safe-extract.py` extracts uploaded archives with no limit on entry count, directory depth, total entries, or output size. A small malicious archive containing a large number of directory or file entries causes the filebeat processing container to create an unbounded number of filesystem objects, exhausting inodes or filesystem metadata and denying service to the processing pipeline and any service sharing the same mount. Version 26.07.0 fixes the issue.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Vulnerability Type
不加限制或调节的资源分配
Vulnerability Title
Cybersecurity and Infrastructure Security Agency Malcolm 资源管理错误漏洞
Vulnerability Description
Cybersecurity and Infrastructure Security Agency Malcolm是Cybersecurity and Infrastructure Security Agency组织的一款网络流量与日志分析平台。 Cybersecurity and Infrastructure Security Agency Malcolm 26.07.0之前版本存在资源管理错误漏洞,该漏洞源于safe-extract.py提取上传归档文件时未限制条目数量、目录深度、总条目数或输出大小,可
CVSS Information
N/A
Vulnerability Type
N/A