Your comment seems to imply an out of bounds access (read past the allocated buffer), but heartbleed has no out of bounds access.
Instead, it's a problem of malloc (and even more so openssl's freelist scheme) returning non-zeroed memory which can (and often does) hold previously allocated data combined with read(2) not overwriting the whole buffer and not checking read(2)'s return value, which means the aforementioned previously allocated data gets sent back.
http://security.stackexchange.com/questions/55343/how-to-exp...
It takes a special skill to eliminate all the non-essential information and produce something truly simple to understand, like the comic.
The only reason I ever manage to be short in text form is being able to go back and delete.
http://www.kevinandkell.com/2000/kk0730.html