CVE-2021-43579
HIGHhtmldoc <= 1.9.13 - Remote Code Execution via Crafted BMP File in image_load_bmp()
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2021-43579. PoCs published by wulfgarpro.
AI-analyzed exploit summary This exploit demonstrates a stack buffer overflow in HTMLDOC's BMP reader (`image_load_bmp`) by leveraging a negative `biClrUsed` value to overflow a fixed-size stack buffer. The payload overwrites the saved return address, leading to arbitrary code execution or a crash.
Description
A stack-based buffer overflow in image_load_bmp() in HTMLDOC <= 1.9.13 results in remote code execution if the victim converts an HTML document linking to a crafted BMP file.
Exploits (1)
This exploit demonstrates a stack buffer overflow in HTMLDOC's BMP reader (`image_load_bmp`) by leveraging a negative `biClrUsed` value to overflow a fixed-size stack buffer. The payload overwrites the saved return address, leading to arbitrary code execution or a crash.
References (5)
Scores
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H