Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

swfcombine swf_Relocate() Null-pointer access #26

Closed
lcatro opened this issue Jun 11, 2017 · 0 comments

Comments

Projects
None yet
1 participant
@lcatro
Copy link

commented Jun 11, 2017

Crash : https://raw.githubusercontent.com/lcatro/My_PoC/master/swftools/swfcombine_-t-m-G-B-v-z-f-o_dev_null__swf_Relocate_42B491

Trigger : ./swfcombine -t -m -G -B -v -z -f -o /dev/null swftools/swfcombine_-t-m-G-B-v-z-f-o_dev_null__swf_Relocate_42B491

Crash Detail :

`
fuzzer@ub16x64:~/fuzzing/swftools/src$ ./swfcombine -t -m -G -B -v -z -f -o /dev/null swftools/swfcombine_-t-m-G-B-v-z-f-o_dev_null__swf_Relocate_42B491
NOTICE Combine [(null)]none and [Frame00]swftools/swfcombine_-t-m-G-B-v-z-f-o_dev_null__swf_Relocate_42B491
NOTICE Slave file attached to named object Frame00 (1).
ASAN:SIGSEGV

==18827==ERROR: AddressSanitizer: SEGV on unknown address 0x000000000001 (pc 0x00000040ab6a bp 0x60200000ee30 sp 0x7ffeffe29660 T0)
#0 0x40ab69 in swf_Relocate (/home/fuzzer/fuzzing/swftools/src/swfcombine+0x40ab69)
#1 0x404346 in normalcombine (/home/fuzzer/fuzzing/swftools/src/swfcombine+0x404346)
#2 0x404857 in combine (/home/fuzzer/fuzzing/swftools/src/swfcombine+0x404857)
#3 0x405584 in main (/home/fuzzer/fuzzing/swftools/src/swfcombine+0x405584)
#4 0x7f9a0186982f in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x2082f)
#5 0x401e48 in _start (/home/fuzzer/fuzzing/swftools/src/swfcombine+0x401e48)

AddressSanitizer can not provide additional info.
SUMMARY: AddressSanitizer: SEGV ??:0 swf_Relocate
==18827==ABORTING

`

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
You can’t perform that action at this time.