oss-sec mailing list archives

Re: Thousands of vulnerabilities, almost no CVEs: OSS-Fuzz


From: Bob Friesenhahn <bfriesen () simple dallas tx us>
Date: Tue, 25 Jun 2019 09:51:02 -0500 (CDT)

On Tue, 25 Jun 2019, Matthew Fernandez wrote:

I’m probably telling you things you already know and it sounds like you don’t consider such issues worth addressing, but I just wanted to point out that these are not theoretical. These cause real problems for users and, for open source software, you may not have full control over what toolchain/flags users build your code with.

I think that almost all bugs are issues worth addressing given sufficent resources available to address them. The issue discussed is what proportion of bugs discovered via automated testing and claimed to be "security" issues based on computer analysis are exploitable vulnerabilities which deserve a CVE.

A good point has been made that Linux heap memory allocation behavior may be very different than other OSs and that behavior can also be hardware-specific.

Bob
--
Bob Friesenhahn
bfriesen () simple dallas tx us, http://www.simplesystems.org/users/bfriesen/
GraphicsMagick Maintainer,    http://www.GraphicsMagick.org/
Public Key,     http://www.simplesystems.org/users/bfriesen/public-key.txt

Current thread: