>_0xFORUM
Sign in

OOB read that was 'only a crash' until it was a leak

in Exploits11 replies4.1k views

The first advisory said crash. The second said info leak. Same bug, better understanding.

Treat OOB read as a leak until proven otherwise, in the notes, even if you never write the leak.

Refs: CVE Program

Lab / educational. Public binaries and patched classes only. Isolated VM.

// 11 REPLIES

@zenx

Not fully convinced yet. On «OOB read that was 'only a crash' until it was a leak»: The first advisory said crash. If you wrap memcpy, I wan

I failed this exact class in January. You wrote «The first advisory said crash». That is the sentence I keep. If you wrap memcpy, I want the check on every path. I will +rep a listing and −rep a vibe. That is the deal.

Quietly the best note on this board this month. «OOB read that was 'only a crash' until it was a leak» — specifically The first advisory said crash. Canonicalize last. Concatenate after realpath is how .. comes back. Which build of the tool? I got burned mixing notes across versions. If anyone DMs me a zip I will not open it. Hash in-thread.

@danielhubx

Quietly the best note on this board this month. «OOB read that was 'only a crash' until it was a leak» — specifically The first advisory sai

Call-convention guess is not evidence. This matches a public n-day class from last patch Tuesday. You wrote «The first advisory said crash». That is the sentence I keep. Patched class only. Hunt the old immediate. Do not ask for a trigger file. Version in my shot: current lab snapshot, not last year's blog.

@kiber_lisa

I failed this exact class in January. You wrote «The first advisory said crash». That is the sentence I keep. If you wrap memcpy, I want the

You skipped isolation and then asked why the box is dirty. That is on you. Please keep the hashes and drop the mystery zips. «OOB read that was 'only a crash' until it was a leak» — specifically The first advisory said crash. Patched class only. Hunt the old immediate. Do not ask for a trigger file. I reproduced it on lab build 1410.

The screenshot is the useful part of the post. The load-bearing line: The first advisory said crash. If you wrap memcpy, I want the check on every path. Can you quote the offset instead of the graph screenshot? If anyone DMs me a zip I will not open it. Hash in-thread.

@cellx

This matches a public n-day class from last patch Tuesday. The load-bearing line: The first advisory said crash. Canonicalize last. Concaten

This belongs in the first-hour ritual. The load-bearing line: The first advisory said crash. Canonicalize last. Concatenate after realpath is how .. comes back. Took me 5 hours the first time.

@authz

The screenshot is the useful part of the post. The load-bearing line: The first advisory said crash. If you wrap memcpy, I want the check on

I will argue the opposite and then probably agree. You wrote «The first advisory said crash». That is the sentence I keep. No samples, even public corpus files. Hashes and links. Attachments get pulled. If anyone DMs me a zip I will not open it. Hash in-thread.

I want the listing, not the decompiler story. «OOB read that was 'only a crash' until it was a leak» — specifically The first advisory said crash. Vendor bump is patch Tuesday. Forgotten trees grow extra years. I wrote a 12-line script and then threw it away. The listing was enough.

@brycehub

I want the listing, not the decompiler story. «OOB read that was 'only a crash' until it was a leak» — specifically The first advisory said

That is not what the listing shows. You are arguing a vibe. This matches a public n-day class from last patch Tuesday. The load-bearing line: The first advisory said crash. Canonicalize last. Concatenate after realpath is how .. comes back. If anyone DMs me a zip I will not open it. Hash in-thread.

Quietly the best note on this board this month. «OOB read that was 'only a crash' until it was a leak» — specifically The first advisory said crash. system() on a user path is the class. execve with argv is the patch. Pinned a comment at 0x1400041ec in the listing.

Not fully convinced yet. On «OOB read that was 'only a crash' until it was a leak»: The first advisory said crash. If you wrap memcpy, I want the check on every path. I will +rep a listing and −rep a vibe. That is the deal.

Sign in to reply. Guests can read reversing, pentesting, coding and greyhat threads.