Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Russh: Post-auth remote panic via pty-req with more than 130 terminal-mode records
Vulnerability Description
Russh is a Rust SSH client & server library. Prior to 0.62.4, an authenticated SSH client can cause a denial of service by sending a pty-req channel request with more than 130 terminal-mode records. The parser in russh/src/server/encrypted.rs stores terminal modes in a fixed 130-entry [(Pty::TTY_OP_END, 0); 130] array but continues increasing the mode count, then constructs an out-of-bounds slice and panics before the application pty_request handler runs. The panic terminates the server session task without causing memory corruption. This issue is fixed in version 0.62.4.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Vulnerability Type
对数组索引的验证不恰当
Vulnerability Title
Eugene Russh 输入验证错误漏洞
Vulnerability Description
Eugene Russh是Eugene个人开发者的一个SSH协议实现库。 Eugene Russh 0.62.4之前版本存在输入验证错误漏洞,该漏洞源于解析pty-req通道请求时,终端模式记录超过130个,导致越界切片并触发panic,可能造成拒绝服务。
CVSS Information
N/A
Vulnerability Type
N/A