tl;dr
- overflow the
char
candle counter stored in the wax structure and trigger uaf. - Use the uaf to trigger double free and get shell.
tl;dr
char
candle counter stored in the wax structure and trigger uaf.tl;dr
__GI__IO_file_jumps
.dfprintf
.tl;dr
tl;dr
tl;dr
mmap_threshold
with null and trim top chunk size._IO_buf_base
and brute force to get allocation on stdin.tl;dr
/proc/<pid of child>/mem
tl;dr
tl;dr
tl;dr
tl;dr