A local root vulnerability in glibc
A local root vulnerability in glibc
Posted Oct 4, 2023 6:03 UTC (Wed) by Kamiccolo (subscriber, #95159)Parent article: A local root vulnerability in glibc
Putting an emphasize:
> although we discovered this buffer overflow manually,
> we later tried to fuzz the vulnerable function, parse_tunables(); both
> AFL++ and libFuzzer re-discovered this overflow in less than a second,
> when provided with a dictionary of tunables (which can be compiled by
> running "ld.so --list-tunables").
> although we discovered this buffer overflow manually,
> we later tried to fuzz the vulnerable function, parse_tunables(); both
> AFL++ and libFuzzer re-discovered this overflow in less than a second,
> when provided with a dictionary of tunables (which can be compiled by
> running "ld.so --list-tunables").
*sigh*
