Skip to content
KitploitKITPLOIT
أدواتالمدونة
Log in
إرسال
أدواتالمدونة
إرسال

أدوات الاختراق واختبار الاختراق والأمن السيبراني لترسانتك الأمنية!

Kitploit هو دليل لأدوات الاختراق والأمن السيبراني واختبار الاختراق. اكتشف آخر تحديثات المشاريع للعثور على الثغرات وتحليل الأنظمة وأتمتة الاختبارات وتعزيز أمنك.

··الخلاصات·اتصال·الخصوصية·© 2026 Kitploit

دليل الأدوات

الفئات

عرض جميع الفئات
Loading categories
CVE-2025-20260 — Python-based exploit for CVE-2025-20260 that generates a malicious PDF file and includes core dump analysis capabilities for vulnerability verification. | Kitploit
أدوات/GitHubGitHub/keyuraghao/cve-2025-20260
Payload GenerationVulnerability AnalysisExploitationForensicsBinary Exploitation
GitHubkeyuraghao/cve-2025-20260

CVE-2025-20260

Python-based exploit for CVE-2025-20260 that generates a malicious PDF file and includes core dump analysis capabilities for vulnerability verification.

عرض المستودع
16منذ 12 أياملم تتم المراجعة بعد

الأكثر شعبية

عرض الكل →

اكتشف الأدوات الأكثر استخدامًا من قبل مجتمعنا.

استكشف جميع الأدوات

تصفح مجموعتنا من الأدوات

عرض جميع الأدوات →
مشاركة
المحتوى غير متوفر باللغة المطلوبة. عرض النسخة الإنجليزية.

CVE-2025-20260 - ClamAV PDF Scanning Buffer Overflow (First Public PoC)

First public proof-of-concept for CVE-2025-20260 (CVSS 3.1 base score 9.8, Critical), a buffer-overflow vulnerability in the PDF scanning path of ClamAV. This repository contains a generator for the malicious PDF that triggers the flaw, plus a core-dump analysis documenting the crash.

This PoC was developed and published after the vulnerability was patched and coordinated-disclosed by Cisco/ClamAV. It is provided for defensive research, detection engineering, and education. Do not run it against systems you do not own or have explicit permission to test.

The vulnerability

Per the NVD record and the Cisco advisory:

A vulnerability in the PDF scanning processes of ClamAV could allow an unauthenticated, remote attacker to cause a buffer overflow condition, cause a denial of service (DoS) condition, or execute arbitrary code on an affected device. This vulnerability exists because memory buffers are allocated incorrectly when PDF files are processed.

How the PoC works

ClamAV's PDF parser reads the /Length field of a stream object to size the buffer it allocates for the decoded data. clamshank.py crafts a PDF whose single object declares an oversized, malformed length and carries an ASCII85Decode stream just longer than uint32_MAX / 4 bytes:

1 0 obj
<< /Length 1073741824 444444444444 /Filter /ASCII85Decode >>
stream
... (~1,073,741,825 bytes of ASCII85 data) ...

When ClamAV scans the file, the incorrect length arithmetic leads to a mis-sized buffer allocation and the subsequent decode overflows it, crashing the scanning process (DoS) with the potential for code execution in the ClamAV process context.

Contents

FileDescription
clamshank.pyGenerates clam-cve.pdf, the malicious PDF that triggers the overflow.
HOS Core dump analysis for CVE-2025-20260.pdfCore-dump analysis of the crash, documenting the overflow at fault time.

Usage

python3 clamshank.py          # writes clam-cve.pdf
clamscan clam-cve.pdf         # against a vulnerable ClamAV build, in an isolated VM

Run only against a ClamAV instance you control, in a disposable/isolated environment. The generated file is ~1 GB by design.

Remediation

Upgrade to a patched ClamAV release (see the Cisco advisory for fixed versions). Do not expose PDF scanning of untrusted input on unpatched builds.

Disclaimer

For authorized security research and education only. The author is not responsible for misuse.

تنزيل الأداة