Category: coding/misc


05 Mar 2023

pwn, rev, cve

ImageMagick CVE-2020-10251: Exploitation

This is part 2 in the series on the ImageMagick vulnerability CVE-2020-10251. Part 1 discusses how to trigger the vulnerability and touches on how to recover the OOB heap data. This part will look at crafting suitable exploit files and exfiltrating useful information from the heap, making use of a...


05 Mar 2023

pwn, rev, cve

ImageMagick CVE-2020-10251: Vulnerability analysis

In the past, I had done some research in the automated detection of vulnerabilities in binaries. There were a few vulnerabilities that I used as a benchmark for my algorithm to detect, one of which was CVE-2020-25674. This CVE was a bug in ImageMagick, “a widely deployed, general purpose image...