Systrace before 1.6.0 has insufficient escape policy enforcement.
The product calls free() twice on the same memory address.
Link | Tags |
---|---|
http://www.citi.umich.edu/u/provos/systrace/ | third party advisory |
http://taviso.decsystem.org/research.html | third party advisory |
http://taviso.decsystem.org/research.t2t | third party advisory |
https://www.provos.org/index.php?/archives/2007/12/C2.html | third party advisory |