Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
TinyWeb 0.0.8 Null Pointer Dereference DoS via Malformed HTTP Request
Vulnerability Description
TinyWeb through 0.0.8 contains a null pointer dereference vulnerability that allows unauthenticated remote attackers to crash worker processes by sending a malformed HTTP request line with an invalid version string. The HttpParser::execute() function fails to allocate the Url object when version parsing fails, leaving the url pointer NULL, and buildResponse() subsequently dereferences this NULL pointer without checking the valid_requ flag, producing a SIGSEGV that terminates the worker process and, when repeated across all workers, takes the server permanently offline until manually restarted.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Vulnerability Type
空指针解引用
Vulnerability Title
GeneralSandman TinyWeb 异常处理不当漏洞
Vulnerability Description
GeneralSandman TinyWeb是GeneralSandman个人开发者开源的一款嵌入式Web服务器软件。 GeneralSandman TinyWeb 0.0.8及之前版本存在异常处理不当漏洞,该漏洞源于HttpParser::execute()函数在版本解析失败时未能分配Url对象,导致后续buildResponse()函数解引用空指针,使得未认证远程攻击者通过发送畸形HTTP请求行可导致工作进程崩溃,多次重复可导致服务器永久离线。
CVSS Information
N/A
Vulnerability Type
N/A