3DS Userland Flaws: Difference between revisions
Line 239: | Line 239: | ||
|- | |- | ||
| bossbannerhax | | bossbannerhax | ||
| | | After successfully loading [[Extended_Banner|extended-banner]] data(done when selecting an icon), Home Menu attempts to load "[[CBMD]]" data into a 0x100000-byte heap buffer from the [[BOSS_Services|stored]] SpotPass content. When successful and the magic-number is CBMD, Home Menu then decompresses the exbanner sections into another fixed-size heap buffer, without checking the outsize at all. The main CBMD CGFX code with ExeFS checks the size, but this code doesn't(however this is exbanner "CBMD", not a "normal" CBMD). | ||
Used with menuhax as of v3.2. | |||
| None | | None | ||
| [[11.2.0-35|11.2.0-X]] | | [[11.2.0-35|11.2.0-X]] |