iOS 7.1.x PDF exploit – CVE-2014-4377
isc.sans.edu
isc.sans.edu
No, let's just keep repeating old classic bugs.
OpenBSD's reallocarray(3) is a step in the right direction, but I've always been concerned about the focus on multiplication; needing to allocate x*y+z bytes is a rather common pattern. I suspect there's still plenty of additive arithmetic that goes unchecked.
https://github.com/feliam/CVE-2014-4377
http://blog.binamuse.com/2014/09/coregraphics-memory-corrupt...
That's what our lead C dev says. And I agree, as a C programmer.