CVE-2022-34913
CRITICALmd2roff 1.7 - Stack-based Buffer Overflow via Large Consecutive Character Input
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2022-34913. PoCs published by Halcy0nic.
AI-analyzed exploit summary This repository contains a functional proof-of-concept for CVE-2022-34913, demonstrating a stack-based buffer overflow in md2roff 1.7 via a crafted Markdown file with excessive consecutive characters. The PoC includes replication steps, ASAN output, and identifies the vulnerable code in md2roff.c at line 1095.
Description
md2roff 1.7 has a stack-based buffer overflow via a Markdown file containing a large number of consecutive characters to be processed. NOTE: the vendor's position is that the product is not intended for untrusted input
Exploits (1)
This repository contains a functional proof-of-concept for CVE-2022-34913, demonstrating a stack-based buffer overflow in md2roff 1.7 via a crafted Markdown file with excessive consecutive characters. The PoC includes replication steps, ASAN output, and identifies the vulnerable code in md2roff.c at line 1095.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H