CVE-2017-6193
MEDIUMapng_disassembler < 2.8 - Buffer Overflow via Malformed IHDR Chunk
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2017-6193. PoCs published by Alwin Peppels.
AI-analyzed exploit summary This exploit demonstrates a buffer overflow in APNGDis 2.8 via a malformed PNG file with an oversized IHDR chunk descriptor (0xFFFFFFF4). The PoC triggers a heap corruption, leading to a crash (DoS) and potential arbitrary code execution under controlled conditions.
Description
Buffer overflow in APNGDis 2.8 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted image containing a malformed image size descriptor in the IHDR chunk.
Exploits (2)
This exploit demonstrates a buffer overflow in APNGDis 2.8 via a malformed PNG file with an oversized IHDR chunk descriptor (0xFFFFFFF4). The PoC triggers a heap corruption, leading to a crash (DoS) and potential arbitrary code execution under controlled conditions.
This exploit demonstrates a buffer overflow vulnerability in APNGDis 2.8 by manipulating the width and height fields in a PNG file's IHDR chunk, leading to memory corruption and a segmentation fault. The PoC file triggers invalid memory reads/writes, as confirmed by Valgrind output.
References (4)
Scores
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H