Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
pngcheck-vulns — A repository of proof-of-concept files demonstrating disclosed and patched vulnerabilities in pngcheck (2.4.0 - 3.0.1), including CVE-2020-27818, CVE-2020-35511 and other vulns. | Kitploit
Tools/GitHubGitHub/13m0n4de/pngcheck-vulns
Static AnalysisVulnerability AnalysisExploitationFuzzingBinary AnalysisPapers & ResearchLearning & Education
GitHub13m0n4de/pngcheck-vulns

pngcheck-vulns

A repository of proof-of-concept files demonstrating disclosed and patched vulnerabilities in pngcheck (2.4.0 - 3.0.1), including CVE-2020-27818, CVE-2020-35511 and other vulns.

View Repository
161 year agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Website
Share

pngcheck-vulns

A repository of proof-of-concept files demonstrating disclosed and patched vulnerabilities in pngcheck (2.4.0 - 3.0.1).

Each POC is custom crafted with dedicated generation scripts to trigger specific bugs, covering both CVE-numbered and unnumbered vulnerabilities.

For detailed vulnerability analysis, see my research notes.

Summary

DirectoryTypeDescriptionVersion
vulns-3.0.1Buffer Over-readLOOP chunk: unchecked chunk size<=3.0.1
vulns-3.0.0Buffer Over-readPPLT chunk: first_idx/last_idx handling error<=3.0.0
vulns-2.4.0Null-pointer DereferencesCAL chunk: invalid pointer access<=2.4.0
vulns-2.4.0Buffer Over-readMNG chunks: buffer over-read in 10 chunk types<=2.4.0
CVE-2020-35511Buffer Over-readprint_buffer(): insufficient size validation<=2.4.0
CVE-2020-27818Out-of-bounds Readcheck_chunk_name(): negative array index from char conversion<=2.4.0

Note that some vulnerability types may differ from their CVE descriptions or official classifications. These are subjective categorizations.

Usage

Each vulnerability folder contains:

  • POC files (PNG/MNG format)
  • Python script to generate POC

Some vulnerabilities may not show obvious symptoms when triggered. Recompiling with sanitizer options like -fsanitize=address can help better identify these issues.

For detailed instructions, refer to the README.md in each directory.

References

  • pngcheck Home Page
  • NVD - CVE-2020-27818
  • NVD - CVE-2020-35511
  • giantbranch's blog
  • Portable Network Graphics (PNG) Specification and Extensions
  • MNG (Multiple-image Network Graphics) Format
Download Tool