Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2020-13995 PoC — U.S. Air Force Sensor Data Management System extract75 缓冲区错误漏洞

Source
Associated Vulnerability
Title: U.S. Air Force Sensor Data Management System extract75 缓冲区错误漏洞 (CVE-2020-13995)
Description:U.S. Air Force Sensor Data Management System extract75 has a buffer overflow that leads to code execution. An overflow in a global variable (sBuffer) leads to a Write-What-Where outcome. Writing beyond sBuffer will clobber most global variables until reaching a pointer such as DES_info or image_info. By controlling that pointer, one achieves an arbitrary write when its fields are assigned. The data written is from a potentially untrusted NITF file in the form of an integer. The attacker can gain control of the instruction pointer.
Readme
# Control Flow Hijack Exploit for CVE-2020-13995

Build it:

```
make
```

Run it:

```
make run
```

Mayhem it:

```
docker tag extract75-cve-2020-13955 <your name>/extract75-cve-2020-13955
docker push <your name>/extract75-cve-2020-13955
mayhem run --image <your name>/extract75-cve-2020-13955 \
    --project <your name>/extract75 .
```

(Default runtime is 600 seconds; override with --duration flag)

Need more information? Contact sales@forallsecure.com
File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →