GeographicLib 2.5 is reported as vulnerable to a buffer overflow in the GeoConvert component, specifically in DMS::InternalDecode. Based on the provided information, the flaw occurs during decoding/parsing of DMS (degrees-minutes-seconds) input within GeoConvert. No further technical details about the exact code path, trigger condition, or memory corruption mechanics were provided in the source content.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository is a small exploit PoC consisting of one Python exploit script (Exploit.py) and a README with vulnerability background and duplicated exploit documentation. The exploit targets CVE-2025-60751, described as a stack-based buffer overflow in GeographicLib's GeoConvert/DMS::InternalDecode path. The code is a pwntools-based local ret2libc exploit against a local binary named ./GeoConvert rather than a remote network service. Exploit.py sets context.binary to ./GeoConvert, optionally launches it under GDB, otherwise starts it as a local process with ASAN_OPTIONS adjusted. It dynamically discovers ROP gadgets from the ELF using pwntools (notably 'pop rdi; ret' and 'ret'), then constructs a 64-bit ret2libc chain using a fixed overflow offset of 136 bytes. The script hardcodes a sample libc base and derives system, /bin/sh, and exit addresses from that base, indicating the exploit is intended for controlled lab conditions rather than generalized real-world exploitation. After sending the payload, it probes for shell access by issuing 'id' and checking for 'uid=' before handing control to an interactive session. Main capability: local arbitrary code execution resulting in a shell. There are no network callbacks, C2 endpoints, or remote URLs used by the exploit logic itself. The only fingerprintable operational target is the local file path ./GeoConvert, plus the ASAN_OPTIONS environment setting used during process launch. Overall, this is a real exploit PoC, not a detector, but it is operational only in a narrow environment because libc addresses are not actually leaked dynamically despite comments mentioning ASLR bypass.
This repository contains a proof-of-concept exploit for CVE-2025-60751, a stack buffer overflow in Geographiclib's GeoConvert utility (<= v2.5.1). The exploit is implemented in Python using the pwntools library and targets the local GeoConvert binary. It constructs a ROP chain to execute system('/bin/sh'), providing a shell if successful. The exploit requires the attacker to adjust hardcoded memory addresses for system, /bin/sh, and ROP gadgets, as these may vary due to ASLR or different libc versions. The repository consists of a README.md describing the vulnerability and usage, and exploit.py containing the exploit logic. No network endpoints are involved; the attack vector is local, requiring the attacker to execute the exploit on a system with the vulnerable binary.
3 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.