Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
ION-DTN < 4.2.1-a.1 Denial of Service via canonicalizePayloadBlock() Assertion
Vulnerability Description
ION-DTN before 4.2.1-a.1 contains a denial of service vulnerability that allows unauthenticated remote attackers to crash the ION process by sending a BPv7 bundle with a zero-length payload. The canonicalizePayloadBlock() function in bpsec_util.c passes bundle->payload.length to zco_clone() without validating it against zero, causing a failed CHKZERO assertion that triggers sm_Abort() and terminates the process with SIGABRT before any HMAC verification occurs, requiring no valid key or credential to exploit.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Vulnerability Type
可达断言
Vulnerability Title
NASA Jet Propulsion Laboratory NASA/JPL Interplanetary Overlay Network 异常处理不当漏洞
Vulnerability Description
NASA Jet Propulsion Laboratory NASA/JPL Interplanetary Overlay Network是美国NASA Jet Propulsion Laboratory政府部门的一款深空通信场景下的星际覆盖网络协议软件。 NASA Jet Propulsion Laboratory NASA/JPL Interplanetary Overlay Network 4.2.1-a.1之前版本存在异常处理不当漏洞,该漏洞源于未验证bundle->payload.length
CVSS Information
N/A
Vulnerability Type
N/A