Rating: 5.0
Information leak
A null byte overwrite
_IO_buf_base
with null byte in the stdin structure
_short_buf
which in the stdin structure at first_IO_buf_end
_IO_buf_base
and _IO_buf_end
scanf
to read data__free_hook