
25/04/13, 00:10:13
|
 |
Miembro del foro
Mensajes: 79
|
|
Fecha de registro: mar 2011
Mensajes: 79
Tu operador: Movistar
Mencionado: 1 comentarios
Tagged: 0 hilos
|
|
Cita:
Originalmente Escrito por rangemogger
|
La madre que parió a los Koreanos del demonio...
Cita:
|
However, this code contains a fairly obvious integer overflow in the check: what happens if (start + size) overflows its 32-bit representation, wrapping around to a smaller number? As a result, it's possible to provide pgoff and size values to mmap() that circumvent this check and map arbitrary kernel memory once again.
|
|