Closed abertschi closed 4 years ago
fixes #75 heap overflow due to wrong message size. allocated was only full_msg_size(*header) which did not include a capref as defined in (struct rpc_message) Succeeding mallocs caused data overwrite
full_msg_size(*header)
(struct rpc_message)
Good find, looks right, thank you.
fixes #75 heap overflow due to wrong message size. allocated was only
full_msg_size(*header)
which did not include a capref as defined in(struct rpc_message)
Succeeding mallocs caused data overwrite