
OpenSSL pocs: PKCS#12 stack overflow, CMS IV overflow, OCB infoleak [partial chain]
Not my discovery. Never got around to a proper chain, though it's ~80% smashable; bf_canary needs a real target.
~ glhf
| CVE | Type | Severity | Description |
|---|---|---|---|
| CVE-2025-11187 | Stack Overflow | High | PKCS#12 PBMAC1 keyLength validation bypass |
| CVE-2025-15467 | Stack Overflow | High | CMS AuthEnvelopedData IV length overflow |
| CVE-2025-69418 | Info Leak | Medium | OCB mode partial block encryption failure |
make all OPENSSL_PATH=/path/to/vulnerable/openssl
full-chain/ chains CVE-2025-69418 (ASLR bypass) + CVE-2025-15467 (RCE) against a forking service.
Research/education only. Don't run this against anything you don't own.