oss-sec mailing list archives

Re: Fuzzing findings (and maybe CVE requests) - Image/GraphicsMagick, elfutils, GIMP, gdk-pixbuf, file, ndisasm, less


From: Hanno Böck <hanno () hboeck de>
Date: Mon, 17 Nov 2014 17:21:07 +0100

Am Mon, 17 Nov 2014 14:52:22 +0100
schrieb Jakub Wilk <jwilk () jwilk net>:

* Hanno Böck <hanno () hboeck de>, 2014-11-17, 13:33:
I wasn't able to fuzz a crash out of 7z, arj, msgunfmt (gettext),

https://bugs.debian.org/763820
https://bugs.debian.org/769901

I don't remember the exact details, but I'm pretty sure it took at
most a few hours of afl-fuzzing to find these crashers.

I'd consider "few hours of afl-fuzzing" not to be low hanging fruit,
but opinions may differ on that (I'm currently only focusing on
software where I get the crashers within minutes).

But appart from that: The first bug is marked as fixed but no
indication is given whether the fix went upstream. Did you do that or
should it be reported to gettext?

(Actually that's also a thing I also see far too often - bugs get
reported somehow in public, but the reports don't arrive at the
appropriate upstreams)

-- 
Hanno Böck
http://hboeck.de/

mail/jabber: hanno () hboeck de
GPG: BBB51E42

Attachment: signature.asc
Description:


Current thread: