>_0xFORUM
Sign in

A 'safe memcpy' wrapper that was not

in Exploits7 replies2.7k views

Wrapper took dest, destsz, src, count and then ignored destsz on a path. Patched. Wrappers are code. Review them like memcpy.

If you wrap memcpy and I cannot see the check on every path, I will fail the review.

Refs: CVE Program

Lab / educational. Public binaries and patched classes only. Isolated VM.

// 7 REPLIES

Bookmarking this for the lab wiki. «A 'safe memcpy' wrapper that was not» — specifically Wrapper took dest, destsz, src, count and then ignored destsz on a path. OOB read is a leak until proven otherwise. In the notes, not in a PoC. If anyone DMs me a zip I will not open it. Hash in-thread.

@inf0

Came back to this after a coffee. Still hold. On «A 'safe memcpy' wrapper that was not»: Wrapper took dest, destsz, src, count and then igno

Call-convention guess is not evidence. Good. Dated shot, version in the post. «A 'safe memcpy' wrapper that was not» — specifically Wrapper took dest, destsz, src, count and then ignored destsz on a path. No samples, even public corpus files. Hashes and links. Attachments get pulled. I reproduced it on lab build 1387.

@hexorx

Bookmarking this for the lab wiki. «A 'safe memcpy' wrapper that was not» — specifically Wrapper took dest, destsz, src, count and then igno

Came back to this after a coffee. Still hold. On «A 'safe memcpy' wrapper that was not»: Wrapper took dest, destsz, src, count and then ignored destsz on a path. Vendor bump is patch Tuesday. Forgotten trees grow extra years. Took me 6 hours the first time.

@kevo_prime

If you only have the decompiler, you do not have the bug. On «A 'safe memcpy' wrapper that was not»: Wrapper took dest, destsz, src, count a

I would have written the opposite conclusion a year ago. The load-bearing line: Wrapper took dest, destsz, src, count and then ignored destsz on a path. No samples, even public corpus files. Hashes and links. Attachments get pulled. I will +rep a listing and −rep a vibe. That is the deal.

If you only have the decompiler, you do not have the bug. On «A 'safe memcpy' wrapper that was not»: Wrapper took dest, destsz, src, count and then ignored destsz on a path. Date your heap notes. 2012 grooming diagrams are history. Can you quote the offset instead of the graph screenshot? I reproduced it on lab build 1000.

@lukeprime

This belongs in the first-hour ritual. You wrote «Wrapper took dest, destsz, src, count and then ignored destsz on a path». That is the sent

You are describing a live target. Stop. Patched class only. I disagree with the tone, not the bytes. The load-bearing line: Wrapper took dest, destsz, src, count and then ignored destsz on a path. Patched class only. Hunt the old immediate. Do not ask for a trigger file. I will +rep a listing and −rep a vibe. That is the deal.

This belongs in the first-hour ritual. You wrote «Wrapper took dest, destsz, src, count and then ignored destsz on a path». That is the sentence I keep. Vendor bump is patch Tuesday. Forgotten trees grow extra years. Same class as the January thread, different binary.

Sign in to reply. Guests can read reversing, pentesting, coding and greyhat threads.