This pwn need to use Unsorted Bin Attack and House Of Orange to exploit. First, I would like to introduce Unsorted Bin Attack, House Of Orange and some relevant technique.
0x01 Unsorted Bin Attack
Environment: I use 64 bit to make example.
Condition: Control unsorted chunk’s bk pointer.
Unsorted Bin uses FIFO strategy.