# Binary Parsing and Format Vulnerabilities in Exploitarium: 8 Critical PoCs Explained

> Discover 8 critical PoCs in Exploitarium targeting binary parsing and format vulnerabilities in ELF, ZIP, RIFF, VP9, and SSH. Learn about memory corruption and RCE.

- Repository: [bikini/exploitarium](https://github.com/bikini/exploitarium)
- Tags: deep-dive
- Published: 2026-09-06

---

**Exploitarium contains eight proof-of-concepts targeting binary parsing and file format vulnerabilities across ELF executables, ZIP archives, RIFF-based multimedia containers, VP9 video streams, and SSH protocols, demonstrating memory corruption and remote code execution via malformed metadata fields.**

The Exploitarium repository (`bikini/exploitarium`) is a curated collection of security research demonstrating how improper input validation in binary parsers leads to critical vulnerabilities. Each proof-of-concept targets specific file format implementations—from ELF headers to multimedia codecs—exposing weaknesses in length calculations, header parsing, and structure validation that result in out-of-bounds writes, arbitrary code execution, and information disclosure.

## Objdump DLX Calc: ELF Header Parsing Vulnerability

The **Objdump DLX Calc** proof-of-concept targets GNU `objdump` and its parsing of ELF/DLX object files. The vulnerability resides in how the binary handles malformed headers in DLX architecture objects.

In [[`objdump-dlx-calc-poc/poc.py`](https://github.com/bikini/exploitarium/blob/main/objdump-dlx-calc-poc/poc.py)](https://github.com/bikini/exploitarium/blob/main/objdump-dlx-calc-poc/poc.py), the PoC constructs a crafted ELF file containing a malformed `b"\x7fELF"` header sequence specific to the DLX architecture. When `objdump -g` processes this file, the parser crashes due to improper validation of header metadata, which the exploit chains to launch the system calculator.

```bash

# Download the crafted ELF/DLX payload

curl -L -o payload.bin https://github.com/bikini/exploitarium/raw/main/objdump-dlx-calc-poc/payloads/dlx_calc_aslr_gnu2461_f05_b702fff00_s7043e5ff.bin

# Trigger the parsing crash

objdump -g payload.bin

```

The payload generator constructs headers that bypass initial magic number checks while corrupting subsequent offset calculations, demonstrating how **ELF metadata parsing** without bounds validation leads to memory corruption.

## FFmpeg RASC/DLTA Calc: RIFF Container Buffer Overflow

This proof-of-concept targets **FFmpeg**'s parsing of RIFF-based **RASC/DLTA** audio/video container formats. The vulnerability stems from an out-of-bounds length field in the container header that triggers a buffer overflow during media parsing.

The [[`ffmpeg-rasc-dlta-calc-poc/poc/rasc_dlta_os_helper.py`](https://github.com/bikini/exploitarium/blob/main/ffmpeg-rasc-dlta-calc-poc/poc/rasc_dlta_os_helper.py)](https://github.com/bikini/exploitarium/blob/main/ffmpeg-rasc-dlta-calc-poc/poc/rasc_dlta_os_helper.py) script builds a minimal RASC/DLTA file with a corrupted length value that causes FFmpeg’s internal buffer allocator to underestimate required memory, resulting in heap corruption when the decoder processes the stream.

```bash

# Build the malicious RASC/DLTA container

python3 ffmpeg-rasc-dlta-calc-poc/poc/rasc_dlta_os_helper.py build

# Execute FFmpeg to trigger the overflow

ffmpeg -i rasc_dlta_test.rasc -f null -

```

This demonstrates how **RIFF format parsers** that trust embedded length fields without validation are susceptible to classic buffer overflow attacks.

## Libarchive ZIP Boundary: Size Mismatch Exploitation

The **libarchive** proof-of-concept exploits **ZIP format parsing** when handling archives containing embedded ELF executables. The vulnerability leverages a size boundary discrepancy between the ZIP header's declared uncompressed size and the actual payload size.

In [[`libarchive-zip-debuginfod-size-boundary/make_debuginfod_zip.py`](https://github.com/bikini/exploitarium/blob/main/libarchive-zip-debuginfod-size-boundary/make_debuginfod_zip.py)](https://github.com/bikini/exploitarium/blob/main/libarchive-zip-debuginfod-size-boundary/make_debuginfod_zip.py), the PoC creates a ZIP entry advertising **109 bytes** of uncompressed data while actually containing a full ELF binary. When `libarchive` (via `bsdtar`) parses the header, it reads past the declared boundary, exposing and executing the hidden ELF payload due to insufficient size validation.

```bash

# Generate the size-boundary malicious ZIP

python3 libarchive-zip-debuginfod-size-boundary/make_debuginfod_zip.py create

# Extract triggers execution of the hidden ELF

bsdtar -xf evil.zip

```

This vulnerability highlights the danger of ** trusting size fields in archive headers** without verifying them against actual decompressed data lengths.

## Pillow ImageCMS OOB Write: LittleCMS Transform Parsing

This proof-of-concept targets **Pillow**'s integration with LittleCMS for image color management. The vulnerability exists in the parsing and handling of **image transform formats** when the output mode is modified after initialization.

The [[`pillow-imagecms-output-mode-oob-poc/poc.py`](https://github.com/bikini/exploitarium/blob/main/pillow-imagecms-output-mode-oob-poc/poc.py)](https://github.com/bikini/exploitarium/blob/main/pillow-imagecms-output-mode-oob-poc/poc.py) script creates an image transform with `output_mode` set to `RGBA`, then changes the mode to `L` (grayscale) after the C extension (`_imagingcms`) has already calculated stride values based on the 4-channel RGBA format. This mismatch causes the transform to write 4 bytes per pixel into a 1-byte-per-pixel buffer, resulting in a **heap out-of-bounds write**.

```bash

# Reproduce the heap OOB write

python3 pillow-imagecms-output-mode-oob-poc/poc.py

```

This demonstrates how **format state inconsistencies** between Python wrappers and underlying C parsers can lead to memory corruption vulnerabilities.

## PHP 8.5.7 StreamBucket: Binary Structure Manipulation

The **PHP StreamBucket** proof-of-concept targets the **PHP binary** itself, parsing its internal memory structures to locate writable offsets for code execution. The vulnerability involves manipulating **stream bucket** structures through the SOAP extension.

In [[`php857-streambucket-soap-rce-rpoc/poc/rpoc.php`](https://github.com/bikini/exploitarium/blob/main/php857-streambucket-soap-rce-rpoc/poc/rpoc.php)](https://github.com/bikini/exploitarium/blob/main/php857-streambucket-soap-rce-rpoc/poc/rpoc.php), the PoC scans the running PHP binary to locate a writable `HT_INVALID_IDX` slot in the hash table implementation. It then crafts a malicious SOAP request that overwrites the bucket’s callback pointer, redirecting execution to attacker-controlled shellcode.

```bash

# Target a locally compiled PHP 8.5.7 binary

python3 php857-streambucket-soap-rce-rpoc/poc/rpoc.php --php /path/to/php

```

This illustrates how **parsing ELF metadata** of running interpreters combined with type confusion in internal structures enables reliable remote code execution.

## Redis ELF Metadata Abuse: Runtime Binary Analysis

This proof-of-concept demonstrates how **parsing ELF metadata** of a running process enables sophisticated memory corruption attacks against **Redis**. The PoC analyzes the `redis-server` binary to locate critical offsets for an exploit.

The [[`redis-vset-duplicate-hnsw-id-rce-poc/poc.py`](https://github.com/bikini/exploitarium/blob/main/redis-vset-duplicate-hnsw-id-rce-poc/poc.py)](https://github.com/bikini/exploitarium/blob/main/redis-vset-duplicate-hnsw-id-rce-poc/poc.py) script performs the following **binary parsing** steps:
1. Reads the ELF headers to determine the PIE base address
2. Locates the GOT entry for `free`
3. Calculates the offset to libc's `system` function

With these offsets, the exploit uses Redis protocol commands to corrupt memory and execute arbitrary commands.

```bash

# Launch against a fresh redis-server binary

python3 redis-vset-duplicate-hnsw-id-rce-poc/poc.py --redis /usr/bin/redis-server

```

This vulnerability class shows how **ELF parsing of live binaries** bypasses ASLR and enables reliable exploitation of memory corruption bugs.

## Libssh2 CVE-2026-55200: SSH Packet Length Validation

The **libssh2** proof-of-concept targets **SSH packet parsing** vulnerabilities, specifically **CVE-2026-55200**. The vulnerability involves improper validation of packet length fields in the SSH binary protocol.

In [[`libssh2-cve-2026-55200-poc/poc/libpwn_cve_2026_55200_client.py`](https://github.com/bikini/exploitarium/blob/main/libssh2-cve-2026-55200-poc/poc/libpwn_cve_2026_55200_client.py)](https://github.com/bikini/exploitarium/blob/main/libssh2-cve-2026-55200-poc/poc/libpwn_cve_2026_55200_client.py), the PoC crafts an SSH packet with a malformed length field that bypasses libssh2’s internal bounds checks. When the vulnerable server processes this packet, the miscalculation leads to heap overflow and remote code execution.

```bash

# Start the vulnerable listener

python3 libssh2-cve-2026-55200-poc/poc/libpwn_cve_2026_55200_server.py

# Send the malicious packet

python3 libssh2-cve-2026-55200-poc/poc/libpwn_cve_2026_55200_client.py

```

This demonstrates how **binary protocol parsers** that rely on attacker-supplied length fields without sufficient validation are vulnerable to memory corruption.

## VLC VP9: Video Resolution Parser Crash

The **VLC** proof-of-concept targets the **VP9 video format parser** in VLC media player. The vulnerability is triggered by malformed resolution metadata within the VP9 bitstream.

The [[`vlc-vp9-reschange-crash-poc/poc.py`](https://github.com/bikini/exploitarium/blob/main/vlc-vp9-reschange-crash-poc/poc.py)](https://github.com/bikini/exploitarium/blob/main/vlc-vp9-reschange-crash-poc/poc.py) generates a malicious VP9 stream that flips resolution fields mid-stream, causing VLC’s parser to dereference a null pointer when handling the dimension change. This results in a denial-of-service crash exploitable for further memory corruption.

```bash

# Feed the malicious VP9 bitstream to VLC

python3 vlc-vp9-reschange-crash-poc/poc.py

```

This highlights how **multimedia format parsers** handling complex state transitions (like resolution changes) without proper null checks are vulnerable to stability issues and potential code execution.

## Summary

- **Exploitarium** demonstrates eight distinct classes of binary parsing vulnerabilities across executable, archive, multimedia, and protocol formats.
- **ELF metadata parsing** bugs in `objdump` and runtime Redis analysis enable attackers to bypass ASLR and execute arbitrary code.
- **ZIP and RIFF container formats** are vulnerable to length field manipulation, leading to buffer overflows and hidden payload execution.
- **Image transform parsers** in Pillow suffer from state inconsistency vulnerabilities that cause heap out-of-bounds writes.
- **SSH and PHP binary protocols** can be subverted by malformed length fields and structure manipulation, resulting in remote code execution.

## Frequently Asked Questions

### What are binary parsing vulnerabilities?

**Binary parsing vulnerabilities** are security flaws that occur when software reads and interprets binary data formats (like ELF, ZIP, or RIFF) without properly validating structure sizes, offsets, or metadata fields. These vulnerabilities often lead to memory corruption, information disclosure, or arbitrary code execution when the parser encounters malformed or maliciously crafted input that violates format specifications but is processed anyway.

### How does the Libarchive ZIP size boundary attack work?

The Libarchive attack works by creating a **ZIP header** that advertises a specific uncompressed size (109 bytes) while the actual payload contains a larger **ELF binary**. When `libarchive` parses the header, it trusts the size field and reads beyond the allocated buffer during extraction, exposing the hidden ELF executable. This demonstrates how improper validation of size metadata in archive formats can lead to information disclosure and arbitrary code execution.

### What makes the Pillow ImageCMS vulnerability an OOB write?

The Pillow vulnerability is an **out-of-bounds (OOB) write** because the Python wrapper modifies the `transform.output_mode` from `RGBA` to `L` after the underlying C extension (`_imagingcms`) has already allocated a buffer and calculated stride values based on the 4-byte RGBA format. When the transform executes using the new 1-byte grayscale mode, it writes 4 bytes of data per pixel into a 1-byte-per-pixel buffer, overflowing the heap allocation and corrupting adjacent memory.

### Why is ELF metadata parsing dangerous in the Redis PoC?

**ELF metadata parsing** is dangerous because the Redis PoC reads the target binary's Program Headers and Section Headers to calculate the exact memory addresses of the Procedure Linkage Table (PLT) and Global Offset Table (GOT). By parsing the ELF structure, the attacker bypasses **Address Space Layout Randomization (ASLR)** and locates the precise offset of `system()` in libc, enabling reliable exploitation of memory corruption vulnerabilities that would otherwise require brute-forcing or information leaks.