>_0xFORUM
Sign in

A patched n-day in a library we vendor and forgot to bump

in Exploits32 replies800 views

The upstream patched. Our tree did not. That is our CVE now, socially, even if the number stays upstream.

Vendor bumps are patch Tuesday. Put them on the same calendar.

Refs: CVE Program

Lab / educational. Public binaries and patched classes only. Isolated VM.

// 32 REPLIES

Bookmarking this for the lab wiki. The load-bearing line: The upstream patched. No samples, even public corpus files. Hashes and links. Attachments get pulled. Was this on the licensed corpus or a crackme you wrote? I wrote a 12-line script and then threw it away. The listing was enough.

Please keep the hashes and drop the mystery zips. You wrote «The upstream patched». That is the sentence I keep. No samples, even public corpus files. Hashes and links. Attachments get pulled. I still have the snapshot named expl-246-pre.

@andrewflex

Please keep the hashes and drop the mystery zips. You wrote «The upstream patched». That is the sentence I keep. No samples, even public cor

Call-convention guess is not evidence. Came back to this after a coffee. Still hold. On «A patched n-day in a library we vendor and forgot to bump»: The upstream patched. If you wrap memcpy, I want the check on every path. I reproduced it on lab build 1035.

If you only have the decompiler, you do not have the bug. «A patched n-day in a library we vendor and forgot to bump» — specifically The upstream patched. OOB read is a leak until proven otherwise. In the notes, not in a PoC. Took me 10 hours the first time.

I will argue the opposite and then probably agree. «A patched n-day in a library we vendor and forgot to bump» — specifically The upstream patched. Vendor bump is patch Tuesday. Forgotten trees grow extra years. Pinned a comment at 0x140002421 in the listing.

Also: Vendor bump is patch Tuesday. Forgotten trees grow extra years.

@build

I will argue the opposite and then probably agree. «A patched n-day in a library we vendor and forgot to bump» — specifically The upstream p

I dumped after OEP and then did this. On «A patched n-day in a library we vendor and forgot to bump»: The upstream patched. A saturating add that hangs is not a complete patch. Hunt the hang too. Can you quote the offset instead of the graph screenshot? I still have the snapshot named expl-246-pre.

@charly

I dumped after OEP and then did this. On «A patched n-day in a library we vendor and forgot to bump»: The upstream patched. A saturating add

You are describing a live target. Stop. Patched class only. I ran this on a licensed corpus binary. On «A patched n-day in a library we vendor and forgot to bump»: The upstream patched. Canonicalize last. Concatenate after realpath is how .. comes back. If anyone DMs me a zip I will not open it. Hash in-thread.

I reproduced it twice before I believed you. The load-bearing line: The upstream patched. Vendor bump is patch Tuesday. Forgotten trees grow extra years. I will +rep a listing and −rep a vibe. That is the deal.

@cryptb

I reproduced it twice before I believed you. The load-bearing line: The upstream patched. Vendor bump is patch Tuesday. Forgotten trees grow

I will argue the opposite and then probably agree. You wrote «The upstream patched». That is the sentence I keep. system() on a user path is the class. execve with argv is the patch. I will +rep a listing and −rep a vibe. That is the deal.

This is the kind of thread that should be a sticky and is not. On «A patched n-day in a library we vendor and forgot to bump»: The upstream patched. OOB read is a leak until proven otherwise. In the notes, not in a PoC. I wrote a 12-line script and then threw it away. The listing was enough.

@dfir

This is the kind of thread that should be a sticky and is not. On «A patched n-day in a library we vendor and forgot to bump»: The upstream

Quote the bytes or sit down. Quietly the best note on this board this month. The load-bearing line: The upstream patched. Vendor bump is patch Tuesday. Forgotten trees grow extra years. After you did that, did the decompiler pick it up or did you dump? Pinned a comment at 0x140004e56 in the listing.

@emmyfresh

Quietly the best note on this board this month. The load-bearing line: The upstream patched. Vendor bump is patch Tuesday. Forgotten trees g

I want the listing, not the decompiler story. The load-bearing line: The upstream patched. Canonicalize last. Concatenate after realpath is how .. comes back. Same class as the January thread, different binary.

Same wall I hit last quarter. The load-bearing line: The upstream patched. system() on a user path is the class. execve with argv is the patch. I reproduced it on lab build 1180.

Also: If you wrap memcpy, I want the check on every path.

The screenshot is the useful part of the post. The load-bearing line: The upstream patched. A saturating add that hangs is not a complete patch. Hunt the hang too. Took me 4 hours the first time.

@grid

The screenshot is the useful part of the post. The load-bearing line: The upstream patched. A saturating add that hangs is not a complete pa

You skipped isolation and then asked why the box is dirty. That is on you. I dumped after OEP and then did this. On «A patched n-day in a library we vendor and forgot to bump»: The upstream patched. A saturating add that hangs is not a complete patch. Hunt the hang too. Version in my shot: current lab snapshot, not last year's blog.

If you only have the decompiler, you do not have the bug. The load-bearing line: The upstream patched. OOB read is a leak until proven otherwise. In the notes, not in a PoC. Did you force-create the function or did auto-analysis luck into it? Took me 2 hours the first time.

I will argue the opposite and then probably agree. On «A patched n-day in a library we vendor and forgot to bump»: The upstream patched. If you wrap memcpy, I want the check on every path. I still have the snapshot named expl-246-pre.

@ismailtrend

I will argue the opposite and then probably agree. On «A patched n-day in a library we vendor and forgot to bump»: The upstream patched. If

I tried the naive path first and wasted a morning. On «A patched n-day in a library we vendor and forgot to bump»: The upstream patched. If the thread slides toward a live target, lock it. I will report it. I wrote a 12-line script and then threw it away. The listing was enough.

@kelvinpro

I tried the naive path first and wasted a morning. On «A patched n-day in a library we vendor and forgot to bump»: The upstream patched. If

That is not what the listing shows. You are arguing a vibe. Quietly the best note on this board this month. On «A patched n-day in a library we vendor and forgot to bump»: The upstream patched. Date your heap notes. 2012 grooming diagrams are history. I still have the snapshot named expl-246-pre.

I failed this exact class in January. The load-bearing line: The upstream patched. Patched class only. Hunt the old immediate. Do not ask for a trigger file. My note id for this: f6-27.

@loadx

I failed this exact class in January. The load-bearing line: The upstream patched. Patched class only. Hunt the old immediate. Do not ask fo

I disagree with the tone, not the bytes. «A patched n-day in a library we vendor and forgot to bump» — specifically The upstream patched. Vendor bump is patch Tuesday. Forgotten trees grow extra years. Did you force-create the function or did auto-analysis luck into it? Version in my shot: current lab snapshot, not last year's blog.

I still keep a paper notebook for this kind of note. The load-bearing line: The upstream patched. A saturating add that hangs is not a complete patch. Hunt the hang too. I will +rep a listing and −rep a vibe. That is the deal.

@netsec

I still keep a paper notebook for this kind of note. The load-bearing line: The upstream patched. A saturating add that hangs is not a compl

Call-convention guess is not evidence. I would have written the opposite conclusion a year ago. The load-bearing line: The upstream patched. Date your heap notes. 2012 grooming diagrams are history. I will +rep a listing and −rep a vibe. That is the deal.

@olamidee

I would have written the opposite conclusion a year ago. The load-bearing line: The upstream patched. Date your heap notes. 2012 grooming di

Same wall I hit last quarter. On «A patched n-day in a library we vendor and forgot to bump»: The upstream patched. Date your heap notes. 2012 grooming diagrams are history. My note id for this: f6-31.

If you only have the decompiler, you do not have the bug. «A patched n-day in a library we vendor and forgot to bump» — specifically The upstream patched. Vendor bump is patch Tuesday. Forgotten trees grow extra years. Pinned a comment at 0x14000046a in the listing.

@richmondx

If you only have the decompiler, you do not have the bug. «A patched n-day in a library we vendor and forgot to bump» — specifically The ups

I disagree with the tone, not the bytes. You wrote «The upstream patched». That is the sentence I keep. No samples, even public corpus files. Hashes and links. Attachments get pulled. Same class as the March thread, different binary.

@secdev

I disagree with the tone, not the bytes. You wrote «The upstream patched». That is the sentence I keep. No samples, even public corpus files

You skipped isolation and then asked why the box is dirty. That is on you. I would have written the opposite conclusion a year ago. You wrote «The upstream patched». That is the sentence I keep. Vendor bump is patch Tuesday. Forgotten trees grow extra years. I will +rep a listing and −rep a vibe. That is the deal.

Please keep the hashes and drop the mystery zips. On «A patched n-day in a library we vendor and forgot to bump»: The upstream patched. No samples, even public corpus files. Hashes and links. Attachments get pulled. What did you key the join on — PID or process GUID? If anyone DMs me a zip I will not open it. Hash in-thread.

@stage

Please keep the hashes and drop the mystery zips. On «A patched n-day in a library we vendor and forgot to bump»: The upstream patched. No s

Good. Dated shot, version in the post. «A patched n-day in a library we vendor and forgot to bump» — specifically The upstream patched. If you wrap memcpy, I want the check on every path. I wrote a 12-line script and then threw it away. The listing was enough.

I will argue the opposite and then probably agree. You wrote «The upstream patched». That is the sentence I keep. If the thread slides toward a live target, lock it. I will report it. Version in my shot: current lab snapshot, not last year's blog.

@victor_lee

I will argue the opposite and then probably agree. You wrote «The upstream patched». That is the sentence I keep. If the thread slides towar

That is not what the listing shows. You are arguing a vibe. The screenshot is the useful part of the post. «A patched n-day in a library we vendor and forgot to bump» — specifically The upstream patched. OOB read is a leak until proven otherwise. In the notes, not in a PoC. I wrote a 12-line script and then threw it away. The listing was enough.

@white

The screenshot is the useful part of the post. «A patched n-day in a library we vendor and forgot to bump» — specifically The upstream patch

Came back to this after a coffee. Still hold. «A patched n-day in a library we vendor and forgot to bump» — specifically The upstream patched. Patched class only. Hunt the old immediate. Do not ask for a trigger file. I wrote a 12-line script and then threw it away. The listing was enough.

Sign in to reply. Guests can read reversing, pentesting, coding and greyhat threads.