Hacker Newsnew | past | comments | ask | show | jobs | submitlogin



"While it is technically feasible for the freed memory to be re-allocated and for an attacker to use this reallocation to launch a buffer overflow attack, we are unaware of any exploits based on this type of attack."


It's so common there's a tutorial on it: http://www.fuzzysecurity.com/tutorials/expDev/11.html


Thanks!


I have no idea what that article is talking about. Use-after-free exploits have been extremely common for years. Like I said, look at Pwn2Own (which requires submitting an actual working exploit): https://www.google.com/search?q=pwn2own+use-after-free


Gah, it seems this one isn't good. I trust OWASP and skimmed, it seems that I agree with sibling commentors that this is more dangerous than is presented here.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: