Skip to content

Latest commit

 

History

History

CVE-2004-1275

Folders and files

NameName
Last commit message
Last commit date

parent directory

..
 
 
 
 

CVE-2004-1275

Experiment Environment

CentOS 6.5

INSTALL & Configuration

wget https://github.com/mudongliang/source-packages/raw/master/CVE-2004-1275/html2hdml-1.0.3.tar.gz
tar -xvf html2hdml-1.0.3.tar.gz 
cd html2hdml-1.0.3/
./configure
make

Problems in Installation & Configuration

How to trigger vulnerability

./html2hdml < 61.html > 61.hdml

PoCs

html2hdml Buffer Overflow in remove_quote() Lets Remote Users Execute Arbitrary Code

HTML2HDML File Conversion Buffer Overflow Vulnerability

HTML2HDML 1.0.3 - File Conversion Buffer Overflow

Vulnerability Details & Patch

Root Cause

In convert.c, remove_quote() copies any amount of data to a limited-size print_buf array.

Stack Trace

References