My favorites | Sign in
Google
                
New issue | Search
for
| Advanced search | Search tips
Issue 56: Native Client Unmapping Vulnerability
3 people starred this issue and may be notified of changes. Back to list
Status:  Fixed
Owner:  b...@google.com
Closed:  Apr 2009
Security-Contest
Type-Defect


Sign in to add a comment
 
Reported by mark.dowd, Mar 12, 2009
Team: Beached As

After validation has taken place, an application is able to arbitrarily
unmap parts of the text section and then map in new pages at the free
location. Execution will then run into this newly mapped page. New pages
will not be marked executable, but this is not a problem if DEP isn't
enabled (current compilations don't seem to have DEP enabled for Vista.)
unmap1.zip
268 KB Download
Comment 1 by nativeclient.admin, Mar 12, 2009
Verified as an issue.
Status: Accepted
Owner: b...@google.com
Labels: Type-Defect
Comment 2 by nativeclient.admin, Apr 10, 2009
Fix released in build 57.
Status: Fixed
Sign in to add a comment