Linux Heap Exploitation Intro Series: Riding free on the heap – Double free attacks!
ID: d02be05f-16da-566a-83b6-c14e7b57a546
STIX ID: report--d02be05f-16da-566a-83b6-c14e7b57a546
Feed Name: SensePost Blog
Threat Score
This blog post explains double-free heap vulnerabilities in user-space glibc allocators and demonstrates multiple proofs-of-concept using normal and fastbins to leak allocator metadata (including main_arena->top), bypass ASLR, and overwrite __malloc_hook to obtain arbitrary code execution, with gdb walkthroughs and code snippets.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
