logo

Linux Heap Exploitation Intro Series: Set you free() – part 2

ID: 7f9969b1-786d-5d86-91cc-44629ee43494

STIX ID: report--7f9969b1-786d-5d86-91cc-44629ee43494

Feed Name: SensePost Blog

Threat Score
30/100

Date Published: 2018-09-06

Date Updated: 2026-04-29

...
...

This blog post documents exploit-development for a heap-based buffer overflow in the apngopt PNG optimizer. It explains how crafted APNG chunk sizes and heap massaging can produce controlled fastbins/unsorted-bin metadata corruption, demonstrates a proof-of-concept file and debugging techniques (gdb/villoc), and discusses limitations (ASLR, allocator checks) that prevented full instruction-pointer control.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.