It’s probably worth noting that although the bundled utilities are
pretty buggy, there are also several bugs affecting the libtiff
library itself that can be hit with afl if you clean up the
utility-level bugs first; these affect ImageMagick and any tools that
rely on libtiff to display untrusted images.
I reported some privately to the maintainers few weeks ago (before
your report, in fact), but haven’t had a lot of success so far….
Hi Sandro,
As I commented before, we are bound by policy that is out of my personal reach at the moment.
I can tell you, however, that when any independent researcher looks into the HTTP cookie parsing function in the
RomPager 4.07 binary, his bounds will not be checked.
Cheers,
Shahar
From: Sandro Gauci [mailto:sandro () enablesecurity com]
Sent: יום ו 19 דצמבר 2014 09:57
To: Michal Zalewski
Cc: Shahar Tal; fulldisclosure () seclists…
Well noted.
I do trust members of this list to help release the information I couldn’t.
Cheers,
Shahar
________________________________
From: Michal Zalewski
Sent: Friday, December 19, 2014 6:56:20 AM
To: Shahar Tal
Cc: fulldisclosure () seclists org
Subject: Re: [FD] The Misfortune Cookie Vulnerability
I think you might have accidentally pasted the wrong link. This one
doesn’t seem to contain additional information.
in their software development kits Microsoft typically ships
Visual C++ (cross) compilers with headers and libraries,
including the MSVCRT for both static and dynamic linking.
The compiler(s) and the libraries are almost never updated (the
only update I know is <https://support.microsoft.com/kb/949408>),
not even when a vulnerability has been detected and patched;
sometimes they are even outdated when the SDK ships.
The most technical it seems to get is the following:
<quote>
The Misfortune Cookie vulnerability is exploitable due to an error within
the HTTP cookie management mechanism present in the affected software,
allowing an attacker to determine the ‘fortune’ of a request by
manipulating cookies. Attackers can send specially crafted HTTP cookies
that exploit the vulnerability to corrupt memory and alter the application
state. This, in…
Libtiff provides support for the Tag Image File Format (TIFF), a widely
used format for storing image data.
—————-
Software Version
—————-
All tests were performed using libtiff 4.0.3
———–
Description
———–
Fuzzing bmp2tiff, using the afl-fuzzer, revealed an integer overflow
issue related to the dimensions of the input BMP image. The issue
resulted in an out-of-bounds…
=====[Alligator Security Team – Security Advisory]========
– Graylog2-Web LDAP Injection – CVE-2014-9217 – Author: José Tozo <
juniorbsd () gmail com > =====[Table of
Contents]================================== 1. Background 2. Detailed
description 3. Other contexts & solutions 4. Timeline 5. References
=====[1. Background]====================================== Graylog2 is a
free and open source system that allows you to centralize,…