Citizenlab discovered BLASTPASS, a 0day being actively exploited in the image format WebP. Known as CVE-2023-4863 and CVE-2023-41064, an issue in webp’s build huffman table function can lead to a heap buffer overflow. This vulnerability is very interesting and I’m excited to share with you what I learned.
Want to learn hacking? Signup to (ad)
Buy my shitty font: (ad)
WebP Fix Commit: /902bc9190331343b2017211debcec8d2ab87e17a
Citizenlab:
Ben Hawkes:
Software Updates
Apple
Chrome
Firefox
Android
Whose CVE is it Anyway?
References:
2014 bug introduction
://
enough.c
Thanks to:
Chapters:
00:00 - Intro to CVE-2023-4863
01:32 - Most Valuable Vulnerability?
03:02 - Heap Overflow Related to Huffman Trees
03:58 - Learning about Huffman Codes
06:24 - What are Huffman Tables?
10:24 - Hardcoded Table Sizes (enough.c)
12:21 - Code Walkthrough - BuildHuffmanTable()
13:04 - The code_lengths[] and count[] Arrays
15:14 - Difference Between Compression and Decompression!
17:04 - Outro
=[ ❤️ Support ]=
→ per Video:
→ per Month:
2nd Channel:
=[ 🐕 Social ]=
→ Twitter:
→ Streaming:
→ TikTok: @liveoverflow_
→ Instagram:
→ Blog:
→ Subreddit:
→ Facebook:
1 view
0
0
7 years ago 00:03:23 4
FakesApp: A Vulnerability in WhatsApp
9 years ago 00:01:25 45
A Vulnerability in Google Chrome DRM Lets Attackers Steal Protected Content Easily
5 years ago 01:18:31 1
A Beautiful Vulnerability- Indie/Folk Playlist, 2020
7 years ago 00:03:39 52
Lorena Gómez - Vulnerable A Ti
4 years ago 00:24:54 1
Exploiting (and Patching) a Zero Day RCE Vulnerability in a Western Digital NAS
5 years ago 00:50:55 1
Артём Шишкин — Vulnerability is a lucky bug
9 years ago 00:11:31 20
Kali Linux Tools - CMSmap (A simple CMS vulnerability Scanner)
2 years ago 00:21:21 1
let’s play with a ZERO-DAY vulnerability “follina”
3 years ago 00:06:52 1
Set Up a Vulnerable Target Computer with DV-Pi (Damn Vulnerable Pi) [Tutorial]
10 months ago 00:24:13 1
¿RUSI4 ES VULNERABLE FRENTE A UCR4NIA?
5 years ago 00:02:27 45
Friendship & Vulnerability
10 years ago 00:21:48 34
The Power of Vulnerability - Brene Brown
6 years ago 00:03:01 1
How to Turn Vulnerability into a Superpower
12 years ago 00:50:58 36
Brene Brown on The Power of Being Vulnerable
1 year ago 00:18:00 1
A Vulnerability to Hack The World - CVE-2023-4863
2 years ago 00:01:05 1
A TROUBLED HEART IS A VULNERABLE HEART!!
8 years ago 00:00:34 423
The vulnerability series by a Syrian refugee Abdallah Omar.
12 years ago 00:06:40 15
Absolute Vulnerability
13 years ago 00:02:15 22
Robbie Williams - Take The Crown: “There’s a vulnerability to the bravado...“
1 year ago 00:16:00 2
Automating a File Disclosure Vulnerability to Crawl Website Source
7 years ago 00:01:35 20
Critical RCE Vulnerability Found in Over a Million GPON Home Routers
10 years ago 01:07:29 6
12. Real Estate Finance and its Vulnerability to Crisis
9 years ago 00:09:55 9
3.2 - What is a disease? Vulnerable to robust
4 years ago 00:02:19 1
M1RACLES: Bad Apple!! on a bad Apple (M1 vulnerability)