abctab2ps 多个 缓冲区溢出漏洞

abctab2ps 多个 缓冲区溢出漏洞

漏洞ID 1108344 漏洞类型 缓冲区溢出
发布时间 2004-12-15 更新时间 2005-01-10
图片[1]-abctab2ps 多个 缓冲区溢出漏洞-安全小百科CVE编号 CVE-2004-1260
图片[2]-abctab2ps 多个 缓冲区溢出漏洞-安全小百科CNNVD-ID CNNVD-200501-084
漏洞平台 Windows CVSS评分 10.0
|漏洞来源
https://www.exploit-db.com/exploits/25029
https://www.securityfocus.com/bid/82611
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200501-084
|漏洞详情
abctab2ps是一个乐谱排版程序,它将ABC语言转化为postscript。abctab2ps1.6.3中存在多个缓冲区溢出漏洞。subs.cpp中write_heading函数及parse.cpp中trim_title函数均存在缓冲区溢出,这使得攻击者可利用特别构造的ABC文件执行任意代码。
|漏洞EXP
source: http://www.securityfocus.com/bid/12028/info

abctab2ps is reported prone to a remote buffer overflow vulnerability. This issue arises because the application fails to carry out proper boundary checks before copying user-supplied data in to sensitive process buffers. It is reported that this issue can allow an attacker to gain unauthorized access to a computer in the context of the application.

This vulnerability exists in the 'trim_title()' function.

An attacker can exploit this issue by crafting a malicious ABC file that contains excessive string data, replacement memory addresses, and executable instructions to trigger this issue.

If a user obtains this file and processes it through the application, the attacker-supplied instructions may be executed on the vulnerable computer. It is reported that successful exploitation may result in a compromise in the context of the application.

abctab2ps version 1.6.3 is reported prone to this vulnerability. It is likely that other versions are affected as well.

https://github.com/offensive-security/exploit-database-bin-sploits/raw/master/bin-sploits/25029.zip
|受影响的产品
abctab2ps abctab2ps 1.6.3
|参考资料

来源:XF
名称:abctab2ps-trimtitle-bo(18584)
链接:http://xforce.iss.net/xforce/xfdb/18584
来源:XF
名称:abctab2ps-writeheading-bo(18583)
链接:http://xforce.iss.net/xforce/xfdb/18583
来源:MISC
链接:http://tigger.uic.edu/~jlongs2/holes/abctab2ps.txt

相关推荐: HostAdmin – Full Path Disclosure

HostAdmin – Full Path Disclosure 漏洞ID 1054089 漏洞类型 发布时间 2003-08-12 更新时间 2003-08-12 CVE编号 N/A CNNVD-ID N/A 漏洞平台 PHP CVSS评分 N/A |漏洞来…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享