Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2024-45870 PoC — Bandisoft BandiView 安全漏洞

Source
Associated Vulnerability
Title:Bandisoft BandiView 安全漏洞 (CVE-2024-45870)
Description:Bandisoft bandiview是韩国Bandisoft公司的一款图像查看器和编辑器软件。 Bandisoft BandiView 7.05版本存在安全漏洞,该漏洞源于精心制作的POC文件在sub_0x3d80fc中容易受到错误访问控制的攻击。
Description
bandiview (7.05) vuln PoC | CVE-2024-45870, CVE-2024-45871, CVE-2024-45872
Readme
# bandiview-7.05-vuln-PoC
This repository contains a PoC for vulnerabilities uncovered in Bandiview 7.05 using fuzzing

- [CVE-2024-45870](https://nvd.nist.gov/vuln/detail/CVE-2024-45870) ( JXR File Parsing DoS Vulnerability )
 - [CVE-2024-45871](https://nvd.nist.gov/vuln/detail/CVE-2024-45871) ( PSD File Parsing DoS Vulnerability )
 - [CVE-2024-45872](https://nvd.nist.gov/vuln/detail/CVE-2024-45872) ( PSD File Parsing Stack Buffer Overflow )


### Details
- Software: [BandiView](https://kr.bandisoft.com/bandiview/)
- Version: v7.05 (2024/7/15, BuildNo=26122)

### Credit
- JaeHo Cho (@Jaecho6053)
- SongHyun Bae (@bshyuunn)
- JunSeo Bae (@V0xe1)
- LeeDong Ha (@GAP-dev)

<br>

<table>
  <tr>
    <th>Bandiview Changes Log</th>
  </tr>
  <tr>
    <td>
      <a href="https://heasarc.gsfc.nasa.gov/FTP/software/fitsio/c/docs/changes.txt">
        <img width="602" alt="image" src="https://github.com/user-attachments/assets/f09aee30-c6fc-43bf-b07c-fce59ca96cf6" />
      </a>
    </td>
  </tr>
</table>
File Snapshot

[4.0K] /data/pocs/5f5bb0154a90e9112e8945247262103f0f7d68f6 ├── [4.0K] CVE-2024-45870 │   ├── [187K] PoC.jxr │   └── [ 1] README.md ├── [4.0K] CVE-2024-45871 │   ├── [1.4K] PoC.psd │   └── [ 1] README.md ├── [4.0K] CVE-2024-45872 │   ├── [1.4K] PoC.psd │   └── [ 1] README.md └── [1008] README.md 3 directories, 7 files
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.