logoalt Hacker News

skupigtoday at 12:09 AM0 repliesview on HN

The article glosses over this, but it looks like the next variable in the struct is conveniently the first parameter to the function, so you can run arbitrary code with system() or whatever. But, yeah, you would need some other exploit to defeat ASLR.