This bug surfaces when a fwrite() is done followed by an fread(), it allows for up to 4095 bytes of heap disclosure. Could potentially be used for a ASLR bypass in python or something.
more here...........http://www.youtube.com/watch?v=yxxGT4aE7lI
more here...........http://www.youtube.com/watch?v=yxxGT4aE7lI