boundary tag being overwritten

Viewed 366

I'm writing an allocator as a school project to replace the reel malloc, the Boundaries Tags (where you write as metadata before and after each allocated block the size of the block and if it is used or free) seems to be a good technic, but I wonder one thing, what is going on if the users's write beyond the range he required allocation for and rewrite your tags,then your malloc is totally broken ? Is it ok or did I miss something ?

1 Answers

Yes, malloc/free behave unexpectedly and may crash.
Here is an example for input of 15 bytes to a dynamically allocated buffer of 10 bytes:
Free crash example due to boundary tag override As you can see, free crashes and output an appropriate message about the overwritten boundary tag.
You can take a look at the source of ptmalloc in Glibc [1] to identify the specific places in the library.

In fact, this situation is so bad that it can even cause a security breach.
Most heap implementations (and Glibc in particular) use doubly linked list to organize free chunks of data (using pointers for the next and previous elements).
Overflowing the boundary tag, and consecutively the pointers of the element list, may allow an attacker to execute an arbitrary (and possibly malicious) code.
For more details about this exploit, please see [2,3].

[1] http://www.malloc.de/malloc/ptmalloc2.tar.gz
[2] Once upon a free(). http://phrack.org/issues/57/9.html
[3] Vudo - An object superstitiously believed to embody magical powers. http://phrack.org/issues/57/8.html

Related