CVE-2025-47256
MEDIUMLibxmp < 4.6.2 - Stack-Based Buffer Overflow via Malformed Pha Format Tracker Module
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2025-47256. PoCs published by SexyShoelessGodofWar.
AI-analyzed exploit summary This repository contains a functional PoC for CVE-2025-47256, a stack-based buffer overflow in libxmp's depack_pha() function. The PoC includes a crafted malicious file (poc_data.h) and a C program that triggers the vulnerability by loading the file via libxmp.
Description
Libxmp through 4.6.2 has a stack-based buffer overflow in depack_pha in loaders/prowizard/pha.c via a malformed Pha format tracker module in a .mod file.
Exploits (1)
This repository contains a functional PoC for CVE-2025-47256, a stack-based buffer overflow in libxmp's depack_pha() function. The PoC includes a crafted malicious file (poc_data.h) and a C program that triggers the vulnerability by loading the file via libxmp.
References (3)
Scores
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L