oss-sec mailing list archives

Re: Fuzzing findings (and maybe CVE requests) - Image/GraphicsMagick, elfutils, GIMP, gdk-pixbuf, file, ndisasm, less


From: Hanno Böck <hanno () hboeck de>
Date: Thu, 20 Nov 2014 13:55:37 +0100

Am Thu, 20 Nov 2014 15:43:15 +0300
schrieb Alexander Cherepanov <cherepan () mccme ru>:

less crashed or imagemagick called from lesspipe?

less itself. I tried with disabled lesspipe. Seems to be some kind of
unicode multibyte char decoding issue. Probably unrelated to gif.
It's only exposed with asan or valgrind.

Interesting: With all its power afl wasn't able to find this issue.

-- 
Hanno Böck
http://hboeck.de/

mail/jabber: hanno () hboeck de
GPG: BBB51E42

Attachment: signature.asc
Description:


Current thread: