-
Recent Posts
Recent Comments
- strongcourage on Why I stopped fuzzing research
- Bob Friesenhahn on Why I stopped fuzzing research
- #gentoo dev: Why I stopped fuzzing research https://blogs.gentoo.or… | Dr. Roy Schestowitz (罗伊) on Why I stopped fuzzing research
- Ulya on Why I stopped fuzzing research
- ago on Install Gentoo in less than one minute
Archives
- February 2025
- July 2020
- April 2020
- March 2019
- October 2017
- September 2017
- August 2017
- July 2017
- June 2017
- May 2017
- April 2017
- March 2017
- February 2017
- January 2017
- December 2016
- November 2016
- October 2016
- September 2016
- August 2016
- July 2016
- February 2016
- July 2015
- August 2013
- June 2013
- May 2013
- January 2013
- December 2012
- November 2012
- October 2012
- August 2012
- July 2012
- June 2012
Categories
Meta
Monthly Archives: September 2016
libav: null pointer dereference in get_vlc2 (get_bits.h)
Description: Libav is an open source set of tools for audio and video processing. A crafted file causes a NULL pointer access. This issue was discovered the past year, but I didn’t make the report and I didn’t follow the … Continue reading
Posted in advisories, security
Leave a comment
graphicsmagick: NULL pointer dereference in MagickStrlCpy (utility.c)
Description: Graphicsmagick is an Image Processing System. A fuzzing revealed a NULL pointer access in the TIFF parser. The complete ASan output: # gm identify $FILE ASAN:DEADLYSIGNAL ================================================================= ==19028==ERROR: AddressSanitizer: SEGV on unknown address 0x000000000000 (pc 0x7fbd36dd6c3c bp 0x7ffe3c007090 sp … Continue reading
Posted in advisories, security
Leave a comment
ettercap: etterlog: multiple (three) heap-based buffer overflow (el_profiles.c)
Description: ettercap is a comprehensive suite for man in the middle attacks. Etterlog, which is part of the package, fails to read malformed data produced from the fuzzer and then it overflows. Since there are three issues, to make it … Continue reading
Posted in advisories, security
Leave a comment