CVE-2024-35333
HIGHhtml2xhtml 1.3 - Stack-based Buffer Overflow in read_charset_decl
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2024-35333. PoCs published by momo1239.
AI-analyzed exploit summary This repository provides a detailed technical analysis of CVE-2024-35333, a stack buffer overflow vulnerability in html2xhtml version 1.3. It includes root cause analysis, crash reproduction steps, and AddressSanitizer output, demonstrating a clear understanding of the vulnerability mechanics.
Description
A stack-buffer-overflow vulnerability exists in the read_charset_decl function of html2xhtml 1.3. This vulnerability occurs due to improper bounds checking when copying data into a fixed-size stack buffer. An attacker can exploit this vulnerability by providing a specially crafted input to the vulnerable function, causing a buffer overflow and potentially leading to arbitrary code execution, denial of service, or data corruption.
Exploits (1)
This repository provides a detailed technical analysis of CVE-2024-35333, a stack buffer overflow vulnerability in html2xhtml version 1.3. It includes root cause analysis, crash reproduction steps, and AddressSanitizer output, demonstrating a clear understanding of the vulnerability mechanics.
References (1)
Scores
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H