Tencent QQ SuperVideo Remote Denial...

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

QQ is a very popular IM in China developed by Tencent.There exists a remote denial of service vulnerability in QQ when using the SuperVideo chat.Current study showed that the attacker who successfully exploited the vulnerability would cause the remote client crash. There is an attack packet as follows(0x12 length): 03 0f 43 bf //xor char 58 1b ec bf //id1 47 72 c1 9b //id2 00 00 05 00 6b 03 Notice that the following data which loading RTP header and encrypted bitmap data is empty.The following is the pasing code: (LongConnection.dll,version=5.0.200.160) 60A9512F push 2Ch ; size_t 60A95131 lea eax, [ebp-58h] 60A95134 push ebx ; int 60A95135 push eax ; void * 60A95136 mov byte ptr [ebp-4], 1 60A9513A call memset ; memset(lpDataHeader,0x00,0x2c); 60A9513F add esp, 0Ch 60A95142 lea eax, [ebp-58h] ; lpDataHeader 60A95145 mov ecx, esi 60A95147 push dword ptr [ebp+8] 60A9514A push edi 60A9514B push eax 60A9514C call sub_60A95D88 ; get the structure into lpDataHeader 60A95151 test eax, eax...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息