oss-sec mailing list archives

Re: CVE request: out-of-bounds memory access flaw in unrtf


From: Hanno Böck <hanno () hboeck de>
Date: Mon, 22 Dec 2014 08:05:19 +0100

An update here:

unrtf now released 0.21.8 which should contain all the fixes for known
crashers. They also made their project more accessible by using a
public mercurial repository on savannah (they only had an internal
repo before).

I had reported a couple more issues that popped up with address
sanitizer to upstream (it had invalid memory reads even with valid
input files). The latest code didn't expose any more issues within an
hour of running afl.

cu,
-- 
Hanno Böck
http://hboeck.de/

mail/jabber: hanno () hboeck de
GPG: BBB51E42

Attachment: _bin
Description: OpenPGP digital signature


Current thread: