目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2017-5005 PoC — Quick Heal Internet Security、Total Security和AntiVirus Pro on OS X 缓冲区错误漏洞

来源
关联漏洞
标题:Quick Heal Internet Security、Total Security和AntiVirus Pro on OS X 缓冲区错误漏洞 (CVE-2017-5005)
Description:Quick Heal Internet Security、Total Security和AntiVirus Pro on OS X都是基于OS X平台的杀毒软件。 基于OS X平台的Quick Heal Internet Security 10.1.0.316及之前的版本、Total Security 10.1.0.316及之前的版本和AntiVirus Pro 10.1.0.316及之前的版本中存在基于栈的缓冲区溢出漏洞。远程攻击者可借助Mach-O文件中特制的LC_UNIXTHREAD.cmdsize
Description
CVE-2017-5005 for Quick Heal Antivirus
介绍
QuickHeal
=========
CVE-2017-5005 for Quick Heal Antivirus


Advisory
--------
**Improper Restriction of Operations** within the **Bounds of a Memory Buffer** vulnerability.

The software performs operations on a memory buffer, but it can read from or write to a memory location that is outside of the intended boundary of the buffer.


Vulnerability Description
-------------------------
We found that the **Quick Heal Internet Security** is vulnerable to **Out of Bound Write on Stack Buffer** due to improper validation of `LC_UNIXTHREAD.cmdsize` (**Mach-O**).

This vulnerability can be exploited to gain **Remote Code Execution** as well as **Privilege Escalation**.


Proof of Concept
----------------
[![Quick Heal Exploit Demo](https://img.youtube.com/vi/h9LOsv4XE00/0.jpg)](https://www.youtube.com/watch?v=h9LOsv4XE00)


Vendor
------
[http://www.quickheal.co.in/](http://www.quickheal.co.in/)


Products
--------
 * Quick Heal Internet Security 10.1.0.316 and prior
 * Quick Heal Total Security 10.1.0.316 and prior
 * Quick Heal AntiVirus Pro 10.1.0.316 and prior


Disclosure Timeline
-------------------
 * 09 June 2016 – Reported to vendor
 * 11 June 2016 – Received acknowledgement from vendor & Patch released


Author
------
> **Ashfaq Ansari**

> ashfaq[at]payatu[dot]com

> **[@HackSysTeam](https://twitter.com/HackSysTeam) | [Blog](http://hacksys.vfreaks.com/ "HackSys Team") | [null](http://null.co.in/profile/411-ashfaq-ansari)**

> ![Payatu Technologies](http://www.payatu.com/wp-content/uploads/2015/04/Payatu_Logo.png "Payatu Technologies Pvt. Ltd.")

> [http://www.payatu.com/](http://www.payatu.com/ "Payatu Technologies Pvt. Ltd.")


License
-------
Please see the file `LICENSE` for copying permission


------------------------------------------------------------------------
[http://hacksys.vfreaks.com](http://hacksys.vfreaks.com)

![HackSys Team](http://hacksys.vfreaks.com/wp-content/themes/Polished/images/logo.png)
文件快照

登录后查看神龙缓存的 POC 文件快照

登录查看
备注
    1. 建议优先通过来源进行访问。
    2. 本地 POC 快照面向订阅用户开放;当原始来源失效或无法访问时,本地镜像作为订阅权益的一部分提供。
    3. 持续抓取、验证、维护这份 POC 档案需要不少投入,因此本地快照已纳入付费订阅。您的订阅是让这份资料能继续走下去的关键,由衷感谢。 查看订阅方案 →