Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2014-4377 PoC — Apple iOS和Apple TV 整数溢出漏洞

Source
Associated Vulnerability
Title:Apple iOS和Apple TV 整数溢出漏洞 (CVE-2014-4377)
Description:Apple iOS和Apple TV都是美国苹果(Apple)公司的产品。Apple iOS是为移动设备所开发的一套操作系统;Apple TV是一款高清电视机顶盒产品。 Apple iOS 7.1.2及之前版本和Apple TV 6.2及之前版本的CoreGraphics中存在整数溢出漏洞。远程攻击者可通过特制的PDF文档利用该漏洞执行任意代码或造成拒绝服务(应用程序崩溃)。
Readme
CoreGraphics Memory Corruption - CVE-2014-4377
==============================================

Apple CoreGraphics library fails to validate the input when parsing the colorspace specification of a PDF XObject resulting in a heap overflow condition. A small heap memory allocation can be overflowed with controlled data from the input in any application linked with the affected framework. Using a crafted PDF file as an HTML image and combined with a information leakage vulnerability this issue leads to arbitrary code execution. A complete 100% reliable and portable exploit for MobileSafari on IOS7.1.x. can be downloaded from github 

Summary
========
* Title: Apple CoreGraphics Memory Corruption
* CVE Name: CVE-2014-4377
* Permalink: http://blog.binamuse.com/2014/09/coregraphics-memory-corruption.html
* Date published: 2014-09-18
* Date of last update: 2014-09-19
* Class: Client side / Integer Overflow / Memory Corruption
* Advisory: HT6441 HT6443

File Snapshot

[4.0K] /data/pocs/184942d9d24abf57433b007f43e36e1326ea5562 ├── [4.0K] cgi-bin │   └── [ 44] crash.pdf ├── [ 652] index.html ├── [1.4K] iPhone4-7.1.2-patch.sh ├── [1.0K] LICENSE ├── [3.6K] miniPDF.py ├── [ 12K] mkCrash.py ├── [ 960] README.md └── [ 622] run.py 1 directory, 8 files
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.