|
|
|
|
|
by friendzis
1135 days ago
|
|
> How would that look like? How would you reason that it is actually unexploitable? For use-after-free to be exploitable, by definition an attacker must be able to put arbitrary content at the memory region. This is not always easy: may require certain [mis]configuration, data layout and so on. > practically every bug that is related to memory management tends to blow up right into your face, at the most inconvenient time possible. I will not contest this claim, however there is a difference between "blow up" and "exploit". Malicious packet being able to segfault a server is one thing, malicious packet resulting in RCE is quite another. This may be a lost in translation moment when under colloquial use "exploit" does not include DoS. |
|