
Proof-of-concept-Exploit für CVE-2022-36163, eine Format-String-Schwachstelle im pdftoroff hovacui 1.1.0 PDF-Reader, die lokale Denial-of-Service- und Informationspreisgabe über einen manipulierten postsave-Parameter demonstriert.
[Vorgeschlagene Beschreibung] Eine Format-String-Schwachstelle wurde im PDF-Reader pdftoroff hovacui 1.1.0 gefunden. Ein Benutzer kann den zweiten Parameter von sprintf steuern, was zu DoS oder Informationsoffenlegung für weitere Angriffe führen kann.
sprintf(command, output->postsave, fileno, fileno);
[Zusätzliche Informationen] Dies ist nur ein DoS PoC: *** %n in writable segment detected *** [1] 8518 IOT instruction (core dumped) python3 exploit.py
[Schwachstellentyp Sonstiges] Format-String-Schwachstelle.
[Anbieter des Produkts] pdftoroff
[Betroffene Produktcodebasis] hovacui - 1.1.0
[Betroffene Komponente] hovacui.c, Zeile: 1572
[Angriffstyp] Lokal
[Auswirkung Denial of Service] true
[Auswirkung Informationsoffenlegung] true
[Angriffsvektoren] Erstellen Sie eine gefälschte
postsaveund öffnen Sie dann eine PDF-Datei und speichern Sie sie.
[Entdecker] Maher Azzouzi
[Referenz] http://hovacui.com http://pdftoroff.com