
Hands-on lab to learn CVE-2024-4367 (Firefox PDF.js RCE) with PoC generation, vulnerable browser launch, and patched version verification.
[!IMPORTANT] This repository is for learning about vulnerabilities.
This hands-on must be performed on a computer you properly manage. Do not engage in any illegal activities.
The author assumes no responsibility for any damages or liabilities arising from this repository.
Hands-on experience with CVE-2024-4367
python CVE-2024-4367-PoC/CVE-2024-4367.py "alert('document.domain')"
Source: https://github.com/LOURC0D3/CVE-2024-4367-PoC
An attack poc.pdf will be created.
For detailed usage, please refer to the following:
https://github.com/LOURC0D3/CVE-2024-4367-PoC
python firefox.py 125
Open poc.pdf using a vulnerable version of Firefox Nightly.
The first launch will take time because it downloads Firefox Nightly.
Confirm that JavaScript executes and an alert is displayed.
python firefox.py 135
Open poc.pdf with a newer version of Firefox Nightly, confirm that no alert is displayed, and that the vulnerability has been patched.
There is vulnerable-pdf.js containing the vulnerability and invulnerable-pdf.js with the fix.
pdfjs_diff_font_renderer.js is the diff between vulnerable-pdf.js/src/core/font_renderer.js and invulnerable-pdf.js/src/core/font_renderer.js.