Skip to content
KitploitKITPLOIT
工具博客
Log in
提交
工具博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

订阅源联系隐私© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
CVE-2022-44311 — html2xhtml 中的越界读取:CVE-2022-44311 | Kitploit
工具/GitHubGitHub/desmondsanctity/cve-2022-44311
内存取证漏洞分析漏洞利用模糊测试二进制分析学习与教育
GitHubdesmondsanctity/cve-2022-44311

CVE-2022-44311

html2xhtml 中的越界读取:CVE-2022-44311

查看仓库
2123年前尚未审核

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

html2xhtml 中的越界读取:CVE-2022-44311

摘要

Html2xhtml v1.3 被发现存在越界读取漏洞,位于函数 static void elm_close(tree_node_t *nodo) 的 procesador.c 中。攻击者可通过构造的 HTML 文件访问敏感文件或导致拒绝服务(DoS)。

CWE-125 越界读取 是一种软件错误类型,发生在从内存中读取数据时。例如,当程序尝试读取数组末尾之后的数据时可能发生。越界读取可能导致崩溃或其他意外漏洞,并允许攻击者读取本不应访问的敏感信息。

产品

html2xhtml

测试版本

1.3

详情

问题:html2xhtml/src/procesador.c 中的越界读取(GHSA-28fm-qh2h-3mch)

Html2xhtml 是一个命令行工具,可将 HTML 文件转换为 XHTML 文件。Html2xhtml 可以生成符合以下文档类型之一的 XHTML 输出:XHTML 1.0(过渡型、严格型和框架集)、XHTML 1.1、XHTML Basic 和 XHTML Mobile Profile。

该漏洞是由于使用 -t frameset 选项时发生段错误而发现的。段错误或分段错误 是一种由于访问不属于自己的内存而导致的特定错误。它是一种辅助机制,防止内存损坏并引入难以调试的内存错误。

通过使用 Valgrind(一种用于查找 C 和 C++ 程序中堆内存(使用 new 或 malloc 动态分配的内存)访问错误的工具),对段错误进行调试,并在测试用例中报告了 invalid read of size 4:

==1040381== Memcheck, a memory error detector
==1040381== Copyright (C) 2002-2017, and GNU GPL'd, by Julian Seward et al.
==1040381== Using Valgrind-3.18.1 and LibVEX; rerun with -h for copyright info
==1040381== Command: ./src/html2xhtml -t frameset report/vuln/id:000000,sig:11,src:001386+001369,time:12081510,execs:2336913,op:splice,rep:16
==1040381== 
==1040381== Invalid read of size 4
==1040381==    at 0x40E911: elm_close (procesador.c:944)
==1040381==    by 0x410617: err_html_struct (procesador.c:1889)
==1040381==    by 0x40F20A: err_content_invalid (procesador.c:0)
==1040381==    by 0x40F20A: elm_close (procesador.c:959)
==1040381==    by 0x40E7C4: saxEndDocument (procesador.c:233)
==1040381==    by 0x40DF7A: main (html2xhtml.c:117)
==1040381==  Address 0x6f20d4 is not stack'd, malloc'd or (recently) free'd
==1040381== 
==1040381== 
==1040381== Process terminating with default action of signal 11 (SIGSEGV)
==1040381==  Access not within mapped region at address 0x6F20D4
==1040381==    at 0x40E911: elm_close (procesador.c:944)
==1040381==    by 0x410617: err_html_struct (procesador.c:1889)
==1040381==    by 0x40F20A: err_content_invalid (procesador.c:0)
==1040381==    by 0x40F20A: elm_close (procesador.c:959)
==1040381==    by 0x40E7C4: saxEndDocument (procesador.c:233)
==1040381==    by 0x40DF7A: main (html2xhtml.c:117)
==1040381==  If you believe this happened as a result of a stack
==1040381==  overflow in your program's main thread (unlikely but
==1040381==  possible), you can try to increase the size of the
==1040381==  main thread stack using the --main-stacksize= flag.
==1040381==  The main thread stack size used in this run was 8388608.
==1040381== 
==1040381== HEAP SUMMARY:
==1040381==     in use at exit: 88,190 bytes in 13 blocks
==1040381==   total heap usage: 22 allocs, 9 frees, 2,218,413 bytes allocated
==1040381== 
==1040381== LEAK SUMMARY:
==1040381==    definitely lost: 0 bytes in 0 blocks
==1040381==    indirectly lost: 0 bytes in 0 blocks
==1040381==      possibly lost: 0 bytes in 0 blocks
==1040381==    still reachable: 88,190 bytes in 13 blocks
==1040381==         suppressed: 0 bytes in 0 blocks
==1040381== Rerun with --leak-check=full to see details of leaked memory
==1040381== 
==1040381== For lists of detected and suppressed errors, rerun with: -s
==1040381== ERROR SUMMARY: 1 errors from 1 contexts (suppressed: 0 from 0)
==1040419== Memcheck, a memory error detector

来自 Valgrind 的错误日志将我们引向以下发生段错误的函数:

https://github.com/jfisteus/html2xhtml/blob/ffb2f1f12910eb5945413e0bdb9272b508241aa1/src/procesador.c#L940

image

发现该函数中缺少类型检查。用户向函数传递了一个类型为 comment 的节点,而非 element,这导致了越界读取错误。攻击者可以提供畸形的文档,其中包含无效的 ELM_PTR(nodo).contenttype[doctype],从而产生以下汇编比较:

cmp    dword ptr [rbp + rax*4 + 0xc], 4

攻击者可以利用此漏洞,通过构造的文件读取敏感文件、内存或位置。

影响

  • 攻击者可利用此问题读取敏感内存、位置或文件。
  • 攻击者还可通过精心构造的 HTML 文件发起拒绝服务(DoS)攻击。

修复

  • 此漏洞影响使用该软件任何打包版本的用户。GitHub 仓库的 master 分支中已有与此提交相关的修复。
  • 建议用户拉取日期为 2022 年 10 月 25 日或之后的最新软件更新,并在本地编译。错误修复后没有发布新版本或版本号。

资源

  • https://nvd.nist.gov/vuln/detail/CVE-2022-44311
  • jfisteus/html2xhtml#19
  • https://securityboulevard.com/2022/06/what-is-an-out-of-bounds-read-and-out-of-bounds-write-error/
  • https://cwe.mitre.org/data/definitions/125.html

CVSS 基本指标

严重性高 8.1 / 10
攻击复杂度低
所需权限无
用户交互需要
影响范围不变
机密性高
完整性无
可用性高

CVE

  • CVE-2022-44311

致谢

  • 该漏洞由 @Halcy0nic 发现并作为问题报告至 html2xhtml 的软件仓库。
下载工具