CodeJitsu targetted ForAllSecure running CROMU_00051 in round 66. 
 
  Type 2 POV 
 Reading from protected address: 0x4347c000
 0xbaaaad3f : int 128 
  The application exited with a segmentation fault
 0: 0 // esp: 0  
  Execution control corruption via return (return to: 0xbaaaac98). 
 Tracing data from eip: 0x804bb66 tracing source of memory: 0xbaaaac98 (value: 0xbaaaacf1)
 0x804fef7 : receive syscall (return)
 0x8049985 : mov al,byte ptr [ebp-0x29]
 0x8049999 : mov byte ptr [edx+ecx],al
 0x804f6e7 : mov dl,byte ptr [eax]
 0x804f6f7 : mov byte ptr [eax],dl
 0x804f6e7 : mov dl,byte ptr [eax]
 0x804f6f7 : mov byte ptr [eax],dl
 0x804f6e7 : mov dl,byte ptr [eax]
 0x804f6f7 : mov byte ptr [eax],dl
 0x804f6e7 : mov dl,byte ptr [eax]
 0x804f6f7 : mov byte ptr [eax],dl
 0x804f6e7 : mov dl,byte ptr [eax]
 0x804f6f7 : mov byte ptr [eax],dl
 0x804f6e7 : mov dl,byte ptr [eax]
 0x804f6f7 : mov byte ptr [eax],dl
 0x804f6e7 : mov dl,byte ptr [eax]
 0x804f6f7 : mov byte ptr [eax],dl
 0x804f6e7 : mov dl,byte ptr [eax]
 0x804f6f7 : mov byte ptr [eax],dl
 0x804f6e7 : mov dl,byte ptr [eax]
 0x804f6f7 : mov byte ptr [eax],dl
 0x804f6e7 : mov dl,byte ptr [eax]
 0x804f6f7 : mov byte ptr [eax],dl
 0x804f6e7 : mov dl,byte ptr [eax]
 0x804f6f7 : mov byte ptr [eax],dl
 0x804f6e7 : mov dl,byte ptr [eax]
 0x804f6f7 : mov byte ptr [eax],dl
 0x804f6e7 : mov dl,byte ptr [eax]
 0x804f6f7 : mov byte ptr [eax],dl
 0x804f6e7 : mov dl,byte ptr [eax]
 0x804f6f7 : mov byte ptr [eax],dl
 0x804f6e7 : mov dl,byte ptr [eax]
 0x804f6f7 : mov byte ptr [eax],dl
 0x804f6e7 : mov dl,byte ptr [eax]
 0x804f6f7 : mov byte ptr [eax],dl
 0x804f6e7 : mov dl,byte ptr [eax]
 0x804f6f7 : mov byte ptr [eax],dl
 0x804f6e7 : mov dl,byte ptr [eax]
 0x804f6f7 : mov byte ptr [eax],dl
 0x804bb66: ret // address: 0xbaaaac98 value: 0xbaaaacf1  
 Execution of memory occurred that was not part of the initial text sections or an executably allocated page.
 Tracing data from eip: 0xbaaaacf1 tracing source of memory: 0xbaaaacf1 (value: 0x3a2d5857)
 0x804fef7 : receive syscall (return)
 0x8049985 : mov al,byte ptr [ebp-0x29]
 0x8049999 : mov byte ptr [edx+ecx],al
 0xbaaaacf1: push edi // address: 0xbaaaacf1 value: 0x3a2d5857