2 ms·
When in doubt just assume Mark Dowd found it first http://taossa.com/index.php/2007/01/03/attacking-delete-and-delete-in-c http://taossa.com/index.php/2007/01/0
by chrisrohlf 8y ago
When in doubt just assume Mark Dowd found it first http://taossa.com/index.php/2007/01/03/attacking-delete-and-delete-in-c http://taossa.com/index.php/2007/01/03/attacking-delete-and-... (dead link) but see here too http://www.blackhat.com/presentations/bh-usa-07/Dowd_McDonald_and_Mehta/Whitepaper/bh-usa-07-dowd_mcdonald_and_mehta.pdf http://www.blackhat.com/presentations/bh-usa-07/Dowd_McDonal...
- davidtgoldblatt 8y agoOh yes; while certainly mismatched new[]/delete has been a source of problems since forever, what I mean specifically is the new types of exploits possible with the "operator delete(void* ptr, size_t sz)" overload (and its array cousin). Before C++14, using delete (rather than delete[]) to deallocate an array of ints (or other trivially destructible data types) would be safe in practice, even though it was disallowed. In a world with sized deallocation functions, it's exploitable.
- mattbreeden 8y agohttps://web.archive.org/web/20070206052102/http://taossa.com/index.php/2007/01/03/attacking-delete-and-delete-in-c https://web.archive.org/web/20070206052102/http://taossa.com... First archive of the dead link