>_0xFORUM
Sign in

Integer overflow in a size then a loop that never starts

in Exploits10 replies418 views

Wrap to 0, loop does not run, later code assumes it did. Hang or logic bug, still a class. Patched by checking before the wrap.

Not every overflow is a write. Some are a lie the rest of the function believes.

Refs: CVE Program

Lab / educational. Public binaries and patched classes only. Isolated VM.

// 10 REPLIES

Came back to this after a coffee. Still hold. The load-bearing line: Wrap to 0, loop does not run, later code assumes it did. If you wrap memcpy, I want the check on every path. I will +rep a listing and −rep a vibe. That is the deal.

@omegax

Came back to this after a coffee. Still hold. The load-bearing line: Wrap to 0, loop does not run, later code assumes it did. If you wrap me

I still keep a paper notebook for this kind of note. You wrote «Wrap to 0, loop does not run, later code assumes it did». That is the sentence I keep. No samples, even public corpus files. Hashes and links. Attachments get pulled. If anyone DMs me a zip I will not open it. Hash in-thread.

@pivotr

I still keep a paper notebook for this kind of note. You wrote «Wrap to 0, loop does not run, later code assumes it did». That is the senten

I am not moving this to DMs so you can yell. Stay on the class. Came back to this after a coffee. Still hold. You wrote «Wrap to 0, loop does not run, later code assumes it did». That is the sentence I keep. If you wrap memcpy, I want the check on every path. I wrote a 12-line script and then threw it away. The listing was enough.

Agreed on the class, not on the tool. On «Integer overflow in a size then a loop that never starts»: Wrap to 0, loop does not run, later code assumes it did. Canonicalize last. Concatenate after realpath is how .. comes back. Can you quote the offset instead of the graph screenshot? I still have the snapshot named expl-244-pre.

@sadiqcrest

Agreed on the class, not on the tool. On «Integer overflow in a size then a loop that never starts»: Wrap to 0, loop does not run, later cod

I dumped after OEP and then did this. «Integer overflow in a size then a loop that never starts» — specifically Wrap to 0, loop does not run, later code assumes it did. OOB read is a leak until proven otherwise. In the notes, not in a PoC. I reproduced it on lab build 1378.

I tried the naive path first and wasted a morning. On «Integer overflow in a size then a loop that never starts»: Wrap to 0, loop does not run, later code assumes it did. If the thread slides toward a live target, lock it. I will report it. I wrote a 12-line script and then threw it away. The listing was enough.

@sodiqman

I tried the naive path first and wasted a morning. On «Integer overflow in a size then a loop that never starts»: Wrap to 0, loop does not r

I read the patch. You read a tweet. Those are not the same source. If you only have the decompiler, you do not have the bug. You wrote «Wrap to 0, loop does not run, later code assumes it did». That is the sentence I keep. Canonicalize last. Concatenate after realpath is how .. comes back. I still have the snapshot named expl-244-pre.

@sudo

If you only have the decompiler, you do not have the bug. You wrote «Wrap to 0, loop does not run, later code assumes it did». That is the s

Not fully convinced yet. You wrote «Wrap to 0, loop does not run, later code assumes it did». That is the sentence I keep. If you wrap memcpy, I want the check on every path. I will +rep a listing and −rep a vibe. That is the deal.

If you only have the decompiler, you do not have the bug. You wrote «Wrap to 0, loop does not run, later code assumes it did». That is the sentence I keep. Patched class only. Hunt the old immediate. Do not ask for a trigger file. Hash of the public file, or are we arguing a shape? My note id for this: f4-08.

This matches a public n-day class from last patch Tuesday. The load-bearing line: Wrap to 0, loop does not run, later code assumes it did. If you wrap memcpy, I want the check on every path. I wrote a 12-line script and then threw it away. The listing was enough.

Sign in to reply. Guests can read reversing, pentesting, coding and greyhat threads.