THREAT OPS › Threat News › Re: Retrospective by 'gpg.fail' authors
Re: Retrospective by 'gpg.fail' authors
<p>Posted by Lexi Groves (49016) on Sep 15</p>Hi! Author of the talk here.<br /> <br /> To clarify: 1 was actually a 0day. Classic printf injection: %n provides <br /> memory writes,<br /> multiple X.509 certificates in one PEM file to reenter to defeat ASLR, <br /> and from there<br /> it calls execv@plt. The payload just execv's the certificate, which is a <br /> polyglot by<br /> simply in
Original source: https://seclists.org/oss-sec/2026/q3/798