DF-1236 / run.log
RUN_START DF-1236 trm MsgInBuf overflow harness MsgInBuf is 6 bytes (trm.h:168); pMsgPtr started at MsgInBuf[1] Bytes written past end of MsgInBuf[6]: 59 Final MsgCnt (trm.h:173, overwritten path): 0xe0 MsgOutBuf after overflow: a5 a6 a7 a8 a9 aa AdaptStatus=0xab TargetStatus=0xac TagNumber=0xae SRBStatus=0xaf PRIMITIVE CONFIRMED: attacker-controlled bytes written past MsgInBuf[6] into MsgOutBuf and beyond (SRB heap fields). Bug is REAL. EXIT=0