logo

Linux Heap Exploitation Intro Series: Set you free() – part 1

ID: 21a8012a-dbb8-59e6-934b-515d63ad42c2

STIX ID: report--21a8012a-dbb8-59e6-934b-515d63ad42c2

Feed Name: SensePost Blog

Threat Score
45/100

Date Published: 2018-03-15

Date Updated: 2026-04-29

...
...

This post analyzes a vulnerability in APNG Optimizer (apngopt) where a crafted PNG chunk length causes an unsigned integer overflow and subsequent underflow, resulting in an oversized fread into a zero/very-small allocation and a heap overflow. The author details the root cause in read_chunk(), demonstrates how to craft APNG frames to trigger the crash, and outlines exploit-development steps (heap layout control, fastchunk alignment) with debugging tools, with a promise to continue to full exploit construction in a follow-up.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.