3DS Userland Flaws: Difference between revisions
No edit summary |
No edit summary |
||
Line 183: | Line 183: | ||
|- | |- | ||
| [[Nintendo 3DS Sound]] | | [[Nintendo 3DS Sound]] | ||
| | | When a .m4a is loaded, the song name is copied to a 256 byte buffer. When the song name begins with a Unicode BOM marker, it memcpy's the tag using the user-provided length. This gives an arbitrary write which can be used to achieve ROP. | ||
| None | | None | ||
| [[11.2.0-35]] | | [[11.2.0-35]] |