Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

`boost_write` doesn't appear to validate the length of the user supplied buffer before casting and dereferencing either, so that's a kernel-mode OOB read. Not sure how exploitable this actually is though.


lol yep, you're 100% right.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: