From 5e434da085d65e6929e799b1d6c29461bfba8df4 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?J=C3=B6rg=20Siebahn?= Date: Thu, 13 Feb 2025 17:53:08 +0100 Subject: [PATCH] Document fix in version 2.5.2 --- CVE-2024-57699/README.md | 9 +++++++++ CVE-2024-57699/images/fixed-2.5.2.png | Bin 0 -> 23730 bytes CVE-2024-57699/poc/pom.xml | 2 +- .../classes/com/example/CrashTest.class | Bin 1216 -> 1280 bytes 4 files changed, 10 insertions(+), 1 deletion(-) create mode 100644 CVE-2024-57699/images/fixed-2.5.2.png diff --git a/CVE-2024-57699/README.md b/CVE-2024-57699/README.md index ab7286c..282d07a 100644 --- a/CVE-2024-57699/README.md +++ b/CVE-2024-57699/README.md @@ -38,5 +38,14 @@ When running the PoC program depending on an unaffected version, such as 2.4.11, +### [Fixed in version 2.5.2] + +The PoC program exits with code zero and an error message as in older versions. + +
+ + + +
diff --git a/CVE-2024-57699/images/fixed-2.5.2.png b/CVE-2024-57699/images/fixed-2.5.2.png new file mode 100644 index 0000000000000000000000000000000000000000..d5e3ffe595678dbdf42d77d0c677a0de9dad0672 GIT binary patch literal 23730 zcmZsCWl)?!(=9CS?(QDk-8ES75Ok3Q_aMQ8%i<7N+#xswcb3I1xH|-Qhs*nZ->teo z?w_sMr@Cf#p6=;BbNXzgrn({qDk&-q3=D>{lAJaS3;_H-wnavK|Ewoa?SO$X_EwgY z*7ZCzT&u@$H9i@C{zBOCwRBHNj%S2E@P>y%l3CZ9u7rnpU2Cckgo ze~lLZV?R%|m*TW^$uVx?{cO}UFlJOc;IPm>>#*K5>#+Kb)Azqd?~~pP`s}(PhV+x;iPkk3^7^Y;qg!O(eZDsqOvI+WJUmoOz5OzIptrUNhl#>)V zM(DbaeEPlb@cMjnT2`{uwpc$ek44dN|FFOAzjlkX-1KtbdHT%qcmdmYf3eFh32&; z;O*y>Y(~?MxAC{nuoTO!9{SgovZ%J}{>4wr>#c1RqIFm8FSOuzv1!PvhrZk0j7AsK zmt1o&u72foRZ_7t0|CC>cB=UFVsM$k4-0O-^~T*v6YEvpacax%u0%4$Et=3Fh7yfNSPtDa9*}hKbK!Xo$j1?bqi{Keua;)I73f()|6u3PZ=?WL=aT4AKUnOqVU+ z{j5(tH~;u0H?MSR{9kU#&pb?PfkO)VZMWawer=HQ|Jt!0H_mj<3PdqH`TMmA$`wYy zV7GW_hf;b=!OTcN|l^r_Q`;!cFsk=_^ zH;Vrn>+X{D83wlD+|CFmQk(TyG2>`tzD5oL?I-9$=f=~SSF2rB*_nx7ZPK5%q1}*& z!Pimn6S&>9-Z~R%SB`nj8F08))tqkvs2y#~7NoHi-bJdt`}YdZI}%Ci5d^3a-7KU6S;ynzf0ig?$)X=N!(WUqwq$W*tm7%K#1mBA z*8SYfQ2K)qA%yua$MvT2SOY>;825;qB*N}UvH{Ad;Vkzy_IBt+h}W^t zmceO?qMz4W8oFJf=RmM1xdWP(`A)=ca26+4S1I~<;Oe+L%z?7LO0*$mP|$&6Kt3{~ z@yCtVx-ydTQMcyDlcRpACdS?R8>ZTQ7EGc?wuE>>B^CR@vR9t(UdF8qE++mY)6Pp} zJ?oQMd!y({L)2;KlM&uK)X?7H#thC2H!NGV+ri;<5U2_s4mVLVx_I|6oJ^3CsQ) zSfuuX(pINZXleC_*VVgo0iFN$GRe?r^xL0ZnF7`bFYaQ=G+dZ+jJdyhGI9Rr0D3d6 zcXwQ=Pu$yRNGzHp%J{++V!JjvemN~qK?R;~hJS98d~0#I1_gdQ;GKB(6!;dPSvGBZ zch_~daHe+thH5af?Buj%)R0anp3J7n(nA$TT+6q4g@V^f5YReNh$qk3hoev;_aOIC z*ow`3%5Be&=}nvZLWkaO*T;89V~`%=YQo=%0B+F~N14&l*(|KR$Jm2)kzZ zY4rS}QFZE=?fc^O1@1wT!DLts##=g-Z+SGCMsi9jaGlGOhhxb3Vt`+MPPWpdLsyCB z4q`-iH_B2Ca=#RZh&wF(D})cKgkMZFtjFE|Z9R68uLwot;dL^h6{Zb=G<&S&^PuAF zi5lk!M3;Vmfg)IbuA#P5m!%Hq3+EhbDyD&6l6&a1G*|KLKUbM{{mf3s28|~k54L-+ zGXP&`X5dLjRh##KzcVDq2OsNRSGxSe*9Y8rZnK50VyAQi$?GBIcAz5XHACOM*!4<- zT82$xkw*JP#sp;^!-KDmw6C5g)=_!0_E@b-w~F<5rheQ|u(vhAeB+U^#s(`B{E;u* z(TE7mb{5rVf)vYcZpcTH`(8A=sH%{uf-an8(j_5x0mGj#h95Mk#cA#X&N@s^>qh?d z59u6E_pK;1=_)CG$lXq2{GI%Oagwy;P*+`f^ta5=uD44y)gD*atext|UsK>uH~Y1$ z?*V>D8Ig>9lU_Sy-U@U4Ge{tsJ$N1kY(Bd=ky^p2CfKUTO2r#4_@kl6@)JP7gR1`B zr0nnQvrNIaB_s-6JSC<(@gI+*W%r>O0l;V%=j!L^&N!+r+Rq+={85h;%yn7Mb@w(C zlIvPamFZa5VvoM|aP!s<_W{V)A8(M!lI)F9cP}9XJolK^|`te`# zSgYm#&|W86Lh~Q7F~?Tln0Vp&qxJMhQtH&>82;;23+zH>tz}n&w@o{0C)qAerQP3f zi-~Y7Q%1Ke^!G&avDF%;MS8GSD~l|XK*qt&-6UP3YOvic;GDj(!Y|%;z@+zc6cH8a zd>`{>aijB61OK9*N5tLw+4hI7_NoJalG<3g*xOsw`x6yN-DcPA;StS%dD8Y z_N(%zmJ#fbMD|Y)hb3^l`;z{SQ39cBY>&kq{xPUJ9R!fn`U2p4Iua9^LaN$qUDZ#q&<%12hJ^SuJ5wq1=| zzl!RvMlz*(c^pCNXbukxo^4XZTa=0R)x+Lv3tMzI++LQ)v_0X`_c8vPtwkzyBufs1 zn*8V6zn|EeS#=?dLZdkWufi;c{TtFk>pm52Q0nS`L*1PvsQBX7S+e2Bn4^gRM>;#VX=M@~L<%y*Y+oyNYA#}81jxyh;&Q9+>DSZK zuC5~EE~Nw`6bDRk-|?hc9xC~$zsaK+A}ZG>Ay|*YH`UGgRR`1WMQ38~81_mLScym= z`{S_4W2X~KxG*_qCMqB4C)#`*9y$8rM?wB;g|axw0E#JY4E%CkGNvn+mm7@2(C1NJ zisu&A2po72Dx|~5L(RX*ag_xKa7ANOH$I$i4_gV??B(w`PH}T;pW;6~pH$t$__9xc z>lkw(e%AmJrn4McG4aq{P4?Ao@w%1|k`;QrN1tyxarefOW~%A&+)H(L{QzLw3ww~u zem#4uv*)zX>U>tJM*CW~7DM&p+cYqWJU&r93-eCH`UCutk^=SXtUt@F=YUj za<}8x2MS-8_lmZ&1oSC$#AXH@3)qD|Tjr2F9aVd!cn3m31dv;D|L-IjoO4(mrz^q= z79i2C{;jae83w^v@#|p{wCn*#6SVW zy+JfCBx}{7UF| z=LIB8=Ah*R2h~|;X3FpWS8nUMY~MaadNh*+1PE1=TF0}ijUk@B&FH$Wdx!7fGX=Ar zeZ(k2YZNDz1K!TzFxydNS201{x*OHd@aXPHJjfR_1m2$SE~YYH5&p9|LA0c+kFLc=>g!alRGW&gJ<`I$PyDRu)X~!C3Y5 zs9}cn;iiJ>56*&nFjJ!qOu%(F9LIp?Hqp9&o8roTE}GQ{W_&eE5dB>+xvPI?IF%Nc z(*pe-29+8=rf*TYup4-vgnM~-N%GOw4n+z!k`@x{xaO*AdExbr1=PR8Z2N2k=><_1 zkNELoy*zP7Ek2k}YkI4=Tjb(uZ3@E;|U>Jdqe9AN2 zz2w1}BWY)7ELIj-NAo#5)mjQXzhGQL=?eJbc?uc|ztMbvQGDsgb6|)L+U|Nfwa$0` zS9%yEa?*gB2)ilzXBCpqpMt=o0>P02!bHb!$d<~0tOhjYMk2N3l$q#p2S4g)g!VQX z0=vDOkCR7Wwu79fL(#Ze*!%fc3vHDgBM=f zj=80H8{|&~FTQjq>%D#67aa{N!}$6*@0j6$CK}pIt11LKs?mh?B zZrfJq#jc{oUA{+@FI}A+WW0R}jm(<$;iGzClAAR7xEOEhMZdBP?NFiYil#b`Ol^#X zn(5ymOJsHN#zZL3-E6_280SdQ)~eGJsgqZ zq2&Uiumz=Fk^6H%55ccFg);sKhoX~YC23SqcL)SNSX7Sv`oZB71J`xdNyw8!)2xvt zEZ&bAQ=iBgm+;a@eMN$a^QHelnvYw3lpiytlSi}l+L<%x8NnxrBmVR!tM;abhKd0SshGf3N)nq@zX! zKHMUVuGbD0TOBmBULVvBENyo?r}(1!h1s`*KuL{2|FcZE5c&Zp5VtuTr}W z`#ml>=PlAxp>$pF5iW5>te#oH`=)7jve}vF@!N6@dkn%Fi?N*mUcnpymOy(8&gOs} zOftBy@~0V}0Qmrf;gJOcCS1A${6|v2XJpvuC1!w(fBf8-BVS4m0{=p&s z+8fk37Y-xnq}C2n%VeM_YzrfDM3budm5`uaB>R*nJ|Zgrw-_Rs{tmZS-!q2~JD6r} zH1gG*OTw=|mWUm@I=(WxEHiW_Q%4`6lQroiVt#|WC0ek2Mz-YC{g%FP%QfV9JIdC@$Auqz1SC^x zT$f>Dd1wo85e#22+#1HD&j;6)c5xZQgnLY_38O5Js8lYCt>}3;5yv zD&7QAm#~ccI)SXrG%vjl6B@oPVhzL-*OB>c7R!RglsLYcScDNG07VTmo+=)5FEfy; zqsAU}sT;+!k_BQ}RKuoPm@3)eV|Rnxwbd;-bU3Nupe2aHLVkM)B$nIrkxbS~di1Ce z)mvsGmPNe7es5O?48ETCf*pAzMvnq0@M-+<^noV9=n-jjYF2+fDON=bl$#qGTj~4( zN(vkDkEDm9rxcK>RjN4_T4`FQEjwT;A7t5Y?f>i&zCNQLI@>ta!Q}hT9!rlcrz+p)&sO-SD^l%q2EnxWAvDD|6fE0uKoY!Ew z=$avSKfB|?ivkkyr!WEnkC~1VltlhS_}ey-fVv-cl8A$}G-)B$+Ec?Qzz?-wjKn|X z7UWfjt$fwRA;U-rJKmNh@#^p~?D^faP$t>F5&SK2R-FJy<1Pn;sFHR2@CY1l$0saqAnT$`VGH?fRK^0d^%UR?8 zyPr*!a)~v<;xV>-d12D1LbCfbo%ggd!4G^=Ixv}lJrTmm0ypD5F**7}G7I-K%0bs; zgMVdCaa1xJcCgG(3o8@?VkH~fQkpNsUp+{(sQLgjf%wxA6bLv(GO43eq0}M+-`NiP zH9@$8$lL-dQiAI%%<4-nr^aORp)~`K)RvH-0B-7M#DS6+_v+N5rb~@g>NLlo8){}$ zgHG!Pu291fnHtOPq;qRo7wo`OgMrd0%p_F6DEl&N+hlj1K`G@DflgTw8Xc8RV(w$vDRT=!JAGqOa>a0XMdWqs4TT&qPEO*-x zh1e)7o<>fRCsl7X6x1u3nivO(f2GqXJ%3~>gjfq`np5>m@~Q2#bEOnyNKTysj&Quh zMoHX$bBI)uIB=RTYA!eC`yke|lw>7-sOybZ!!9xzdz2MH!Nk`sk0E>_TtWtXsw?V^{r~4c?&V-ZJxh9Z)A|VzQEzx{bDGK8F@Iz zk$Mihpak_s2H@ZdPI+U%YQ2MhR$}8Mvm{?moe07#BNtJPBDmmCQ+hh}$$VH?ft{i> zk%5=IrMZ}x{;_OdfZQLG4wU>sk0W&@TMbm{Ny0?+Ju=bAuF#q-P7TQp89<97A~NBm z+p!{h5MCx#qA1ANXyJVJUVt@Z>DwUrRFn(~*p03po>WC70ioOkwJuIYq-;EYy@B9o zldfQAE#@elG`g7@)TUWE^@;w-IEZjk_n`_9#BRWT0hPAew|Cv9B4*L)IA z!C-^KMxc!MR-)=RCSkNfSE!xv4T51X+M4WRm7J5S;l}k*}xD-`HgpvAV*xC1) z*uvOL*?H!nfN|`7Sx(xi?*^S)KE6ve#XupW#C@X!LL3Qtq=%3iHeohH*NMWUK!mSL!T(7?BAnv3|B^ENJ3GWsWqKFp{J3C1RA&W$wWjRr2fc5kiure1RjXOQ2%u( zHvfu?prl%hD)AE+pXZfLsv#Jyt$9(u#&4#!iyHtv`C;OdjLL#9*2>H8Bbsr;) z>_D^l5f_lmR}knPR)-eJKpf>b`ES-P`+o7<@Ry26<1q4hG|eGU7Dbn%u|$|gMWh9Z z6}2*>3TK~sD*q0$VqX3FFtN5ZbJispy zyfkWO$O#>a!cWG^%37_sn^`6V&A5F(U<_=JxTi*v=K;Tjn(AyrY%Uh+abW6v0?tl0 zcfngb@gG-i2C#~=8!fofw$tRGY8Hyqvlhjb#fpsI8{=x3tf}-m5sfmLtqzaf7wRH*Tr+)LNj&#;MnUG}nABGa6(P5-41QP$av` zA3vcns1B@!NoUyJGNZlgmz?9^7%EidhxlwlhG1f}y|5!X-kbo51+w}?6bAbp@I&qn zTHZz*@R@n!EYf}2OEtIKkL%VTqo@){4qKS=G(h4i5qI^&A!C8;FqGM?`qx9B;br!O z$Ea|Ex;xsIVt>q;#rn1O9cDA ztVYCE29wGaunsC0q+R672tGjF??p6QNhh<1w+vAW>PS$p8WJ|3LO;)yRt0_>QgI%8 zp#d+D#|Rms9#fssu>Z2!HLWTt`oW4G!*HA-qX%Wy{;Jeur}vII4>;oG^5sL1q-@{0 zB)Rq*C0`N#+!A1H5*8S)|HBGCVQ`|@BAE}~1IBvMV1jV;Z(TZTuDPrNNjpoz7@%TYZm#RvXnj9#6ki8(X=ODd)o_6d^&2`A(fDOF z(y|MQ(mW^us&#>GJl2n3{-+4`O*TWaYxpj*_ZsvZL8qeH3*RZl$?K`zBZ0%Seh+($ zG)vg{y9}hhhnKIG5(h)*9kKMCHI1`#p=aIKLR6968Q7($*Q-|RY84Yc#WYl7_ljAVF#h<7wv#TJO=M8~Zn-nPxjUs|@ zd1HvQqXrC)m}rfOyUD_yStoZDrUPjDphl#zma~$VFu`58EOlvU7pUHyl9zkRlCz4A;=i9{@wgaL0P!uf6si=XBAkc@yhrU|6?RQVb-D4`?^Mr5aAw5j1 z+Nq*ow*1Xj4{YZV*a=I756Th|AU&Z$pgBYzMD(^|hq7LUed09W5;xJdvD94%81U#L zgjZ=3!`SRatB5vdlKQmY!++Q(&&X9e$~IW<8FTgyb#aDJi23q;hFK2a?($)A;wWFF zD2Li}-$;S)t<%v7T~%%~C~1cU5DYR*5v@BozEw1NNV`R4PyvktI~GuZ1!g^{Jf@>$ z{W;z<>?rEOqv=v2pS3 znFLRqRGcU6@Sjl@0cqbKhEC%YiRzv2F)9TU^dV7P*4jOUSwwnraQ^`Nj^OrgiWOTT zhlk{Fr?WPJDXTk6KVn@_L$cd?Q_!L=`@>zCr6T494NV!w1%&Ji?(h)^pp-kzx~p*9 zzJ@0qi>R~$=ZXPKkNjzRh+Kx&@Y6BXZSojvOf1DAX`yp0F!MV;XUAVdqatMb8q-0l zoErnWXUyBM7Acb{1SQ7H#g;4bGdIr&hbdM%>Q6<5cmdESo9v+n!&%e_l3Nb;>Y3ZT zPSP$FshE$*Ct`MCrqX+S27rd2n}ZkO3wla~0?92RlV({5Nr*x#f^DzL)RVOR%@-8r z8?elr+h^{wnZbcEm%?^Y#+z<6T}GSRrtZ;1{_!vrIq#i_95p)t3Lh^1IsSM-E>gA} z>aDQ#x*cR+T;X+QyAbbT>(7*prX}3D>H^EPR(%aBvS+7X4t;|+OoUtA*e=Xx>5V)G zKnpFH_O_FzEW$Oitp@1r@)@V zjU8D7lP6_C-_ixN?C<76gjdR;8orT=sZ5PhR2>S$*=>H6K&|sd7VC$jqjFFgRLbKT z%05yA#?&h=2npU1ywsPr=WttkG=ZIgA;s!nSV)i~obBtohnwAiD^uPoh;yXE?;Ga6 z?1y3Id@7q=6t>b zKX?QHWs}N0ra+Nowc1x~bqX?t^ja>{&32p&z#e-$VIgfRO~je2gF6T5n8ma3{zgyq z&iCdKk`R?{;vb&2Jh}1Z+j+9muPiAAoaTs;H)b7N5i4-5lr!5mC?rB_ytj+>c!Hi> z>U%7PoD5O|#2W5v*Emcuf-A&7{r2R{3Z(XhnP6p7Pd<~FBJD6T9#!C0{r0JpdaI2U zPFcv{Em!c0&Gw@rq*N|3YKQ8vccvRll3Cq_CV221SG@44YR!0(3;(oD0w4`aC1IosqK2P7lCL%J7Z4ZZ%NU={h$>%>K6EV%RydVlVv<%?zU z-uqy5DM)lzuliKs+vFPj~ zv*ljsGwhV?4+imLSgvi}<6JI5&aF$o{nkidSznRYPD~G}mqKJc1R#jQEuU-gs-UxD>0m$x!eiQLy9goPl8mOIyYeVLeh!(VDF5KQ)Ssju z7&?=kG!tfCZuc(SQK_rcQTq-*@fOvQ`>4?PQ-EX%uh%A%68-+TKIn8a+%hvJPPjNm z2if1QJFRr5=8c|UC(8Xb8y2l3Ue5RRUDmW|29tsLSm-UMa<%s<$(j@+ECfLZ^?{D{ zc!f&9{_qWb6TU$hpHsp>fL4)8%Zn>8m3uGs(&w66=Z)?El|~UC^8JrWifczW#+~%P zf+;TIOL7GfjQ`bGd1KOn|92QB7M`H~f0b9+{~zU5n558aT6W3T`}KhyMUjpTC&Sv_ zleL7GiNYd)|6Rx1kEX6KR`-1tBmZU{_wNh?y5`Ne$iE*i)bu#KeYns_BE@ukzMRoG zJtE{VPHH=K{qYX^4>s31{BQ3%9x|O)CL~XnO-WW-yz7_$y+qO6DP_3VDJ7BdyB4tN zx=Pwdy-?_edKfJ7I3AVjCOFv)7Czpr22M!2g+vp1;k~?hy@6iNl0uxA)ZMM#TO=6I zX8{G_+P%3Gl3rHNXZjyAaK*3N`kET;R?m5?cCwMuSP%C+j|g9eVF$10ey;>e{K%&| z!|NpBg?w~a`ulR}w)T?Ia@Jv9W?YkdbiEZ#7_kF5+8=WxBjkwk&$7AqzH=0;QosaJA%UVK}-q=J<^ zSvmZ*>Jnb@rMc$G#rL*r|M~OQlT(+6U9m>I|8s@qVU0QMJQ5!9r^7x>w=Zvx`hS2> z(81;pM1dbSf6KNCFcmh~RQD#{Iny;UA0_wiMf)_qDt?Utk6-m~vg$2Ss!VavkkFkw z)&tgWo(CmYvP!$|UL8Es#;fLi&srqj9@9RH*=qKh<8p4>&3mq{`;1^bUZVYR9M1~f z&P-+ZlvPc2Uwyk3tj+W$kSbOa@j83%nPv5hd~)jaa~#^}aU6WSsk%HYX|s5Ji9*54 zH=PIz%JKiVBz_fB;Wn#V^>5KeRVNGGZ|y8eV0+zv8)(QVMf}lrzUS$w zIy+!3<#i@!WuaVmdr%oURrJOK>LNA>gAZqK$2{Z@-^kyGkJ~1J1cV`F%&|nQg|Kt5| z8G6P}#@#!18GS#tP`g%Boc;6RJ=!verXSqeyu6O~A%r6EDqJP1M1M*H0+d(T1UNqb z)6>XIH7jk7*OiDu=k=oK0C{}B&A5NU77B9uVa8Q$!}-T$DDl8N(su9e-|pVc0Zm2^ z^W6Q>#OaEm|MI`rr!UoB>#_b;Ib6M>a7xF7XQlf$$A|M~+ShEjEN(HiwGhEbMOk_3Ue%dvwgS~e}78jms3KXcXGJSuyHEzu%yJdantcZ4lFE5rprR{{jN zw6oWmuk{Cz=e3T+VO|p6Q-|5)Ar!lz$11S!CkW&w;m->2>%&QE3LC>`;SxLjpyyG2gEy_RStL(RF6@xvwb0JAB)5+lL?XOg-Ki0ss(7E3MT&cOr`AByG~K2bw; z^?d)nNS9gAsOnKTmFL)5tLhFzR+>B<%?_Wp(%PS?qw7UI@hMPtQG^v0K^HCJt!)f_VanLpfD*p- z36jf(o^?xPVB`@GA{Yx{d&8}cUA3c<Vs40m0 zsG8QiYx36Cc@b8z31)r`a#7$Ft6O`$)5@t^ttP4)T`)BDC;L52eFt3>bCUd1HJ-?X zaMjZ+Bxp$QXZv^j80E-%;@0wLQ%{knae4kXp7%@7GQly?T}I{=>$zZxy5yH*`KpcT zpX6gQ+3ikKc9vANBln9cC16HfA@`pxst}|^Sh7$Ix$!-3@0H|!8}90bS%Phd)lB`W zs29Yqk&0{{lZ~;G!BUziy=!vcQZ!w$yzc8D`L=a~9n)E@Q#sax{U*sPr94*RsPOhc zj=!k6UvJ}pK%KP-gy`|1$G^~MO!~BDsAJ8W>D90+;BDEhMsRG zaAUv@7Osjl8TFrM&+m(Mm;SDOVO7H!Hc?`*kfA#);O*xG(P{6SS=_@v*Zl?CXq?Tk zQ~_JxOx(4y+Op(1uZ;52W+X=Sfh(8@{pCftnB(jioS8CBIV6xwiQg5&+X#- z@8$NtS#hfhmgG!Ola~zmL@F3Zr6^o+&#imcBind2p5pQOZ*{=)eIX*omzL)TtFh)g z6%($f_Ba3M`&ToapQu&ShBlFSP6q_##;=z2pWgZYFN=zna$jbjmvnE}bs4&q3yGMi zF=e?oW;BfHBo)x%&-+Q>dO^v}q%}TVu1dd@aM5qcGt)r#MCVBD41Gk>BQ{p^flq>`u*ek<}?w z4){I)?`S+85?braE@xHwe1WS(l={{Dt_15-%Y4Ky+tylBHiq>?g7dnfOB6#{$zOyV z|Nec?;B@<|W$~<|vG3EONXQM+9T)ku6DP&pe^1JP8|g0di*(&JT2=H^NPl9v9MS(p zW_oDJrMmG0#}?_jXD0MI{}pbBc-P#2`5Z!4q!vSGP3bI@`!+}w{e$IfKeVOHr3ay^ z&Xf*J6oEAOK2?R?)>+3h3RCO2$(c*whNy2OaE7-fD3sQyH-In%Ua*} zJhMD|_s)?wT;8fsu=dBZBQ+)QYh2Br9)i=VBC)Ll&@&D8qu7i|0s?e2|4z9&L7h)j zId7T{N%hwzoD3LGFXld5$WC{N6^uxpjibV&qz{o^2)BY4wwNT&(Wh(uAL#^;fF}?Mmawz7TJM9mA*u zue5t6U>7|Z0B(M{UxuC%^{~V?zVULJqz>Vh#V+hcQr(5-;CYMOiDjq`L~&bMt<@Y> z3LmW>>}6`xhC>G?aT$09J9jz2nUBdxzy@C|EZ^MCYUPT!hJbkU6HHG^ofgoIV|7y zm%HQ$rlaA73l3C222b42YUgnjCX<2{HyD!I`*kC`Z_yp=!0}${t`p1nhoiygEo@G^ z*yk*^^BjJ(F9+6*PE>ElQZ)L7^>O-DEFXVCH?VbRO;vW)5D(s_6nnEga1FQ?zDHy! zG2u-(ML07{hwi|Q-c1>Qt-e-c1t9Wr9wNx*dlF^R`-_&?5uItqzgK;$n=dY>i1Q}f zBHpqp4M8FOFc{B#bAqid7qn@cv9ooXecN4SUc0*5n6N-~m3N};EAmjb$F<6zl55|H zTMY@8o$#Zr6&4zS3k4PQP(i5<@r06aKvB_KX+9CA%0!^I%>58*Fh_-6l-6sjVf_ZG zaMJkK-$qeMX2+vsy}E}DGuyqnm*VDrnTwqj)bgqhwRK?;1u zyN^*9o3v8v5&|6z)R4Gva|4gUZJV;G!4b6EvpfJ_FDXcLedB`%A5Y?fnHj=YOCNbMZ%UY7-z2L~IPmPg7bL znSk%{5^!~TtWPU&v-ptwAP(37WsNM5Ra|{|&>8P~AUowH{UXiI5EA1}RXeT8kGw}Y z>OTGi0)Sm`4{))Txs);aWa8Z+ z06{c86R9Z`z*FQkn$*B=u>0~}8D7CA!Kl}mHJ;F_aXf!4-#;$O>~Q16g~Pk^HTm<3 za|Sen&o`yrW;2sSYi^P%dkGX0eUckweQGSXP4CzuqKa4GJI=neBg`z=!lWsIX%3w# zbYd~h-?A$D_$$v(Zk!eF+l*}HeA7>){GJ}1T{3a9B11rJtAR7WeXFiMUJWMDIOCr+ z+E=U`m4QH&TPJmq7G+1|V7bVY1B%4lLcF5E2(?>C4$%~omi>DcutBDsV?OLRpT7x{ zC3xJY@;)CjH7+elHT6e6ZtuX55X${G)u-{ zjJ5GDH6$E}3wA4e_(|+t_vmoi10!_JirV??(}l){Fvyey;4O2z(`Q?*c`{71bc;S| zjOnG0M!F}`(2cx5Pe?#fRZd2A=95!!czZ4-R-q0)p7*-Q4Z1knN*?m0LY69Yu`Zt^ zMi0)Yky9YFcimfnu9<=U+IqbmWy-9j5F|A0gI1RyPpofxKM(bfD z2DR89>^HmxyyCstgP5-J&_NIRqoQRd;(|j-y-_CF%r8G}ul6OGpt*pK!Y!Oc^%#G` z!(-aVKXfyZn?nD5kYvnYseOU9=>hieM~aNJ{hjY79m8Wf@7!I+Fuu-?S zzL6qjlt}9Ez+rPAqq4)m;f!cNKZ z0S=AMcI_>}PnQ)+sV=pNUC?Xg(VH8Mq~eN|SIz{7R+gxUJo)6SGP_V+(QB%OdFyh`Msz@P^04Ch`SB|M(o_HH#$}?h3)9 zVbk+6p+2K@a-^s+`GihPvy+5^`v-QyYBxaMmXx}R)S1blx)ZnX$kv~$*L9>pA(1yn z@?CZM*naQ14;wJWW70$;hI-6esD`5N7#Od$jy6f+j#rt<|Jkqq4_>`dtrF{GI5M)( zfWEIk4}~ek*9^_vDa-G2pOJME+dO znj`>qUx-<$1Qll-V=ksIQ9{J&z~}kpOk16r_3*won&;j&jD=y^dscT*iOH}U@w)H0 zNcqR%x%vCoU4D4AScHS8o-X=cIG5=|lzJH@8|z}cL|H1mdf(Fod!t`oKz94`_)T+( z*7nP9&*Hs-E=kAvf=zN3g~!Ve2MGs4eG^{|FpH~^w_#Yq(A~#IJ42z7?iR^IMl78p z^!gP%BVm0b$pqokOJo!3{$mUMQ`fiou4?-jiG>@+NOdJiiN8`~sMmzPF@S-em}i^( z?{P>z$Etovm<}a%s9PsCBA?yh?81NN$@df0+>+g8&MSNi^6Vl$6($!cl%I9Iak%BD zuk-HZYBPfU*A~8(+WII?2_1&USo}>!ri_P`T{{iG(+QIOwIB8~EhJI-5}R7ZBFfD(UG#6m?9=#Kk0j+v~2 zIZ#@{%+BR*_2Mp&@rOGfDh=4gUq_X%(QJF=$Tr-IaW2|Pj$g0GT^7cM-66?905uVm zBC^)d1QUzzHp3mj0~SixUDHZZFJYItF6drVq!^A7aA2@NBVt44VKEZW1-&GI12PaX ztmxnfSLtj0u9<1TWJFe0BhG=u@#hILKz1W>Vm3M_lTI~s%LP7FPlbBPWcuylvq21R z`62CC%_Z-=lESL=mC`&RU2>dYl?QHou?T{34!MyhD(v7ebA}K+ge$c(YkVP#WP@7k z$9GM*5bYi|Ey4T08M8VCr1;1fj)2FBRw6jpD-x{oO7A!C_c*;nIHVtlceD8T*9DLj z-oOAPb(jlX%bFr!Q${h&%r6Kum_#CzQ7RFP`p+5vq9j6+d7L{}=jx+iO-R>x`R)a? zwO@oC;_4!4KCT~I#QCnTnG%8kG9n$lgUTgXBCa1r#Lcxq{F>9sD7Du#;q=4`KK$gt1l;l5%sfip73nGfa08@lkq(Q9eU zPz8ly?E!T;nQLN0?miuxIQ)U$maoWvrQhOT=|~70Td?_uYTz@*;ipMp)s^N%lVWZk zyYBk46+XjJqc*UGMkI}oX7?~3(mTuf|LvJ6K%r4jaUWiIHoma1UwwN`y-(x1k4f0H z3pO3-Zftf^X@aR!r!EgAosRsWL)NntmcjCz*<=a>!Ny8{Hck+xeX62{Qs*V29v0To z8ZM~Sg>nP}r+JZYqumju0&0DIX$`cnH)PHJGHE-=O+d-nhy{;eghx2e_2DF6g4b(1(>>Caa%MML)yDW9z0kBygs8%%W(ozD>58jvG+*8_%l`s$NLi2#P z7&e&oXQ_cJJGB}@c_(d!GT+~Us)A954xb!4px(02$E6Z@+>oXgvWIdkf z7Lj)oH5R9?A}91DLDkL)(fPEZM%v3egeQjSjiX< zBh}JLBCfz=OE)tz;>4YOQ`M>+K~qE*8uCg)pc8`^yCP&Cv%>BaL#$dZ+Qvs)+y%d_ zI;RRI`SA%f&aGP>MeEE_M-7aX#ZLHf+BN^qnmhdkjO4I65aGcqOJQ zg2Zum4cugR)Tt{(*uklz6EEPEQ3@|=@yd*{>HCD4|EHY$3Ti3})CEi@fD{2mM0y7i z0SQPAy$C^i2Y~=0O?nN8AfO;5RB1t)h$1BvK{`@GZ%Qvp4ZV|4JzLM2Gjks9dAc+A z;l3s_nVrerYptyH|KDs_)@D{cA=R2%90^M^$nN@ zA0VJ^%0SknC;I8}`5yN}_On)}JH08K2tOjTGp_X*UMkiB172dd2i;BW*2&m=3d5~@ zE_(czFJXRx9W1cKwW*qewmaTXlf-kigb{u5I>~#D0+xTo)icjK*X_!ydEQz_!lDb4 zB@GMYXJ^#F9h|n(v3Z@3Iy9XN_0p39jrI5pkP@Um9ihip-68fZz;31RW#JYF83}9k z_4`h%tn}&&mbC}LG=)`Jw8Mfo9OCL*pyiEQtfLQ=M~AJKlbFD9zg~wFI@2_~@q{EQ zj{-HM^6(c|7UKOijXCSb^NNKv8o^8&#p*H*jc1=G{k9Z0XWM3kFp#3H%dZE_rM;W{ze@ed zyw6S|S#sj*O^x{poa&b>$A30|LW#a z9s`J7ggdW=1g~@yxkly_U;nc;+V8gnECK@E zCJ2k#Y_lF_LS+*WUJLnLUnb~e#Z-`3YV9hwK{9SWF|FUR^*5kqWWWDQ)Fjrt|jbek6z6+SnKfl@b`Jmnj9*P(3c^?-bIQ#8qS=3>;UP;O9~ zs$r6cT+-$Yflj^C`A9v^=9gihIjrt(v8+bNePMk3lO=X%D?Yqh}tB&x%tUK+zA z!j}-RvJ%;+nq2l55*)ITZ4q)x_zkNd$IyaIqVBkUr$D&!1h#|}L%O1);M|N=q{$hW z^_c7AbJJVxxY)K^7NpM8sD4(B38hyDjTesfmB*scVMfvhQ&tr|jHIjyK-B(;;{3S2F-0?nfp)i(TH=f+G19UhOY)yk zrBSoo>!wKHxUc=b;01vJN+W!Eo#X1ZMOqYOX;zvnA~K%N_xUcC7G?y#4@;YHB#vrn zDH+J@8qzxV%M$>iDBvX*!eZ!}}z*m*bZEs?;as%je^md-rCOXD#YlKQ91>r1o9M;ko)~+ zVP<1Kds8*Lgx(sb3+F}8P>U0c6L)ma$9>rtEJt?rY}}L;CjX8pbmN7d;#*UaJr?}6 zL5lG2V7@*BiLbnkEpHV96{LVnLB7DPqWgW($=z+yMc1x@WDD?YP)P1MBk7dzq!djA zi<45&P#pD57y-WJRy#!N^vc2$lb=D5Pk#F4O5xDTjyc!W?WkWq^vWsLdOo%^OG0YB zN{E>oDb}95g-1bxnl?8*W5+C)x>5ZR-X2^+T>|=sh2*4bon#!_Z?(yyEZ0ObUAU-T z*lC|!$d1#E3h_e1;cq(_VR4RbVYAto=?2RDH${^fLBC!QtR-F%xRCWWqU^ zZoOU^(lG7SVHB9_2INh>=y=wtJ!^hT=cGpWpoJ2hdYWGPspV$k8l#bSqStxSLr>Uc z`#F@4_`+6#SO1*UjH+vx-^Wn()2~pHDH5H@udpH7<>^UBxAgddzGfMfgl+c$vv8o& zGJ~w&C);D$a<>|K`DckKA05~Hn!U%)gVPWu#ymO#OZJt@$tDm13%*B#fwMao8VuS)h?IG%+0iCC_|yfd!kG^SC%cZc&?^-UAOOV&!)D zW4UpQnM!eTW%Znn(cI< zYy3;YED%xztfHCx7@FWx+ZOBbln{J@-9%Y#K0EW@I9SCH=Ei!dWk5c_W~A+)LM-aY z*`BUn?I+rJ01(zl`K3pt(|`#MD2RLE78crvlnf^tPbVn4XKHhPAFQ04tqOi^ZLxlShmoLRQ|cR0$Z`afj7^3;451}hGFlsY`DKr$n%5zlU)V+x!;M36bN=Rr;wb$itk^`3ufZ!~bv*6{ z2_+DBZ>VvtN)-G0D~uwH4bVzl$DF`GmONm3zC7jFNhW-4jpG8{%$9adTrr+xL zbKTg(Tim9c0v2DdD~GmL*gcwiK^SK>ggTrJzZzSpah3XhiFYu0ov=048WCp&v`?+) zzA?y|>+(1w7|^fS!{u6kmMe-`KJ>plV?8(pI``g9Aw#$hfw-K@#f<5_-+flE=~b2k zfp+rT&YXFN%i3VBT+q9ftMi2j@5}uq(~iWVH!Jcj1QgCrU0j(ynZ*i>*C)$X}#`tkng0IKO8 zegzd_lM`sKZWTR}_gDE67gtwn{>R;^>>yl6Pdga47k4>Tq-C?&IE1~oDjj(rc`v|4 zX6<59bp%S%1SMwK^^%v;ZEa>`t1>=_SUpbu z4Xx#9Jv~fEE`?u79NM(ad1;I_B|%#~EvoSrntORMX^f+fcDY4}=pM(iIQ$NYxns~P z=`JIAWjTKQm#hJNi(hL6@tAh^uac?fW)&RjHs<_0=cjA3XHSZAWEW!%yv%1<5LDxh zPuhA>btikSh6_X14n4~e&2T2XSb7?S1o90j&pSv$2^5PTFN@eV8yK{kKwdtKmg8`q zuw8gOzH&U#P`5pUvw7z1RvL75;lj1KmTUVnC&c3zUxPdbt^iAU{7qUh>N_G3tl*G6^k{jT!fEg`K9a zuV}fde0%6z# zQD~PIA9XUxQVJShV{bN!72x>nyHo#jHrJ-$w8Qn&jYYn?6j6_rs zK=yMKJr5vM$c3urH`WdQRAO8{Or0A)XQFPMY<|5TtQj1$TUTHnx&@?2^)=mudY~Xt zUT61+7phAA4}@v4)@o!99r7Xy-JIB&!V7lyA_5YTe#Zygz{2WN58_!acH^hzoEp>5 zqqcstprJE^+TtXFy20Elqd^gK`aVV`VX!J_t=3)49>0>VQbf2MLn3k*H)FZznrI-r|(|>X7En06i89{zFxUWkOY@{z}^UGVSTm`DdZrhMA zadfvxS?KWbqbJ!97lK}9?(pg0!C`kaFkTR5#)G`6+Z9d&wfI#~Zv_I1cDcwsfCG== zB2VflI0GtfpMoU6hT#&EwnXOwPg}~SS3-%QX?J4r8?&G$%cCXfTOs13r;`rbvwflg zZ(53LegUAFrmRvdaOj~cbOZ(>ZGO1btU0UW4TmLWF#`RUcx)puN9%*A3hz8_ZUX!O z10tt+Ab?g5bKuuYKpLQ{V5f}C%-oK|T0jFaUNocnwq%#q45^Y`maQiJG#R#N4g6mFIvettT=f9(A~5jcqPItfNyz8ru*jZLHh(iO3X-JM9iX0v zaq(!a2l1pB5m{UpD2W8T$=*7~YTos|KbPBH3sGT~}8!6sm4_R3f7 zkZ74&=}Q%jhTmMb63L1M%_BnoGXy_r3*_*d0panltk!AHFU+ls6&T_B9?$Grg@new zNveeAI8l^b({cuZcOQpcVGFJf@>?p+D%+AMjE2uo#x3VM?AU#Dn0p=zAvuIq6$N-T zz`e^uwqVZ9RLYZ7UxlkcS=?XQYj@qN@#5fzCjSe>up#bfjCGbb{YQ#|g$PbrhSPm| z=qtc(1|0O<;Ptu2VeOo2ZLaxkkOlq{Hqm-KA%$QwBXuV(Ng6D(UejDf#@~V`A{fQp zMg|mtj-K|o{&SDsVM>q@peHC8qa)+hb}!>Z$$Hl~1@x+_Q1yDzjT|`z>LPvWGAb1c zz|DC0C$8t7I5awEA>!*ow6D{#NfpiQ!241dj?0QtNt~{pun+q{DZk2Rld+=4GIJvW zmrE?Sa5)RG&a(UScRx&zpE)JFf`62PIiFS}^n!Ak&K@LiuB`2+LR$3nY*K(J@{@75 zb}b*tiaPq^lj-W86fDL5+ zr2~4kn#S*b6ICcevHKr(ngQHm=*1{iWCo^-_ z&7qx(%pZD^O||Qf04`N)J>{ApOe3Jx@XVPTq)K4_$d(13Y?Y4YT5$to5bO4bAQ(5# zgOXoY=ayYFgvy9cM`E&u@}4J3l$Z;b^*>0BX-&oam(3>NJOts7Zi-6t*QG2)`elxp$#r7_23TKVXsxewE0T3sydAPT-iT|H-@Zgwge=V-V7IqKSQGnB$Q;LbzA6ACh!= zq<>okEX?T;F=~pUp`L;-ekB$061<1MT5CUmZ#%DAxJ5;RPBtWMm$Ok&YeNf=8I$;X zEOFM(q){p*M{($%R8tu(@a5qUIVC481^S;weEt&n0smYDAYkl1L`^BXP3aOyZidr~ zLsq%&xDBxF(jT8=7(UV2cHq!63wx=~LhTDt1d@Wrb=!Af(JN;GsO z(KvkqSbj1Xynj(K=S9Ajz#7xBFOWA&&~4p_AI5f8}N%82S-E$-b9}WQu;*!Q>6hnzj_b_I(uqNHrb(;MI7AK zB(YGB^aIo82_IcAaE2-VYc%~E!Px{5a2>QWHw}1b**AMA`8ZjKo%k*W0-Ry`fbzh?_{Z18)f zF@ArC*nhWN35Vlo(1djW#rhpFd(|VvzZZe`Dm4Bd?RWg4y&9CUN$=@@1z6++T53?$ JGUX>P{{!$a{0jg8 literal 0 HcmV?d00001 diff --git a/CVE-2024-57699/poc/pom.xml b/CVE-2024-57699/poc/pom.xml index 69503b2..3e02b2f 100644 --- a/CVE-2024-57699/poc/pom.xml +++ b/CVE-2024-57699/poc/pom.xml @@ -12,7 +12,7 @@ net.minidev json-smart - 2.5.0 + 2.5.2 diff --git a/CVE-2024-57699/poc/target/classes/com/example/CrashTest.class b/CVE-2024-57699/poc/target/classes/com/example/CrashTest.class index 798b63f08e94a6ad300586790125532f719e60ed..9382b4941961e74ab1adce7929db80c8c1e31b04 100644 GIT binary patch delta 628 zcmYjPOHUI~6#ni^+uL3TY)fC#%40yO0K<262sJ$Uqty_lH&(6zIow139D^M9p%_mTk+LB`|^; z9C-sbQE&_TSd!y5L$tcHowxSncB^6KXLqIjeATj@!;L5lb*wnD`l2jbt8%kpam=_c zSx=0r-=b@&r-8PHk7Uu^*JJymgegzSJ0y(@+l#vxBQJn)OsHId4M2y7u#IEz^&r<&vI`|2}Tv)VWtbNef!P#jp98}JK!SKJ}F(T`s-jgH5%EP%fuC)7bb?pG1OP?_? z(nhw8;X`V-fMq>S9MNjFq8f=;dR0qC?Nm?TP*IFTTilVw24JFKw_M?LPcyLiE rfmzHEW1jFde7_+$IQxmNU-ThJogt>a(E_2IiZYIVLBxlYuHn%+3%_Ui delta 536 zcmYk2O=}ZT6o#KWlVm32ZS$dHYK>Z>ZIY%nj-P35Qa@XS#)3jhT@*(Np+$<&;6_9j z{s4#h2X4Bq!US57uKgdb-MMg~o{6AdxaU3Reb2r3z2~iSnBMsEbN@5ovFwneY*BGA zDBDzHoVKai%vj7i*j$LIdYoOf@X}o3vV-P|!&RqqLi^cG3o60n^Z>OtlwFCbA(`U1d%!xJ5Fd=Bu Ukr|YRH;r+Q^TRnziefPJ8_l3l1^@s6