Exploit PGP 5.x/6.x/7.0 - ASCII Armor Parser Arbitrary File Creation

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
20738
Проверка EDB
  1. Пройдено
Автор
CHRIS ANLEY
Тип уязвимости
REMOTE
Платформа
MULTIPLE
CVE
cve-2001-0265
Дата публикации
2001-04-09
Код:
source: https://www.securityfocus.com/bid/2556/info

ASCII Armor is a text based encoding format used by PGP (Pretty Good Privacy). While it is possible to encode any file using ASCII Armor, it is used by PGP to encode signature files and public keys to facilitate transmission in e-mail messages.

When a user opens a document for verification in PGP, its corresponding .sig file must be decoded from ASCII Armor.

Due to a flaw in the implementation of the decoder, an arbitrary file can be created on a users system. The file created would be of the attackers choice. 

https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/20738.doc.sig
 
Источник
www.exploit-db.com

Похожие темы