Skip to content

Instantly share code, notes, and snippets.

@heshi906
Created March 30, 2024 15:28
Show Gist options
  • Star 0 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save heshi906/090b647a76981b8aa621e99fd6e1795d to your computer and use it in GitHub Desktop.
Save heshi906/090b647a76981b8aa621e99fd6e1795d to your computer and use it in GitHub Desktop.
CVE-2024-28515(CSAPP Lab3 15-213 Fall 20xx exists RCE)
CVE-2024-28515
[Description]
Buffer Overflow vulnerability in CSAPP_Lab CSAPP Lab3 15-213 Fall 20xx allows a remote attacker to execute arbitrary code via the lab3 of csapp,lab3/buflab-update.pl component.
[Vulnerability Type]
Buffer Overflow
[Vendor of Product]
CSAPP_Lab (Lab of CS:APP3e)
[Affected Product Code Base]
CSAPP Lab3 - 15-213, Fall 20xx (There's only one version.)
[Affected Component]
lab3 of csapp,lab3/buflab-update.pl
[Attack Vectors]
If the server deploys lab3 of csapp_lab, an attacker can access a specific URL to execute arbitrary code.
[Discoverer]
Yuchao He, Yijie Xun, Jiajia Liu, Yuwei Yang, Bomin Mao, Hongzhi Guo (all discoverers from Northwestern Polytechnical University)
[Reference]
- [CSAPP Official Website](http://csapp.com)
- [CSAPP Lab Lab Website](http://csapplablab.com)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment