Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

No this was written about a couple days ago. It frees the memory and because Open uses a LIFO memory allocater it can "safely" assume that whatever was still in there is still in there. I belive that in order to exploit this you would need to exhaust its internal allocator (so that it requests more from the OS) and your payoff would be... having your connection dropped.

This was discovered in the course of someone's attempt to figure out why OpenSSL randomly drops connections when its using a sane/OS supplied allocator.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: