在 9.0 之前的 Vinyl Cache 中,VCL 中字符串类型的 和 方法被发现在工作区存在缓冲区溢出漏洞。该漏洞可被用作远程拒绝服务(DoS)攻击向量,导致子进程发生段错误(segfault)或断言失败(assert)后重启。要有效利用此漏洞,攻击者需事先了解所使用的 VCL 内容,并能够构造一个包含足够长字符串的请求,以在调用点处填满剩余的工作区空间,同时使该请求保持在各种请求大小限制(如 、 等)之内。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Vinyl-Cache | Vinyl Cache | 0 ~ 9.0.2 | - |
|
| Varnish-Software | Varnish Cache | 9.0.0 ~ 9.0.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet