oss-sec mailing list archives

Re: Fuzzing project brainstorming


From: Hanno Böck <hanno () hboeck de>
Date: Thu, 20 Nov 2014 16:50:21 +0100

Am Thu, 20 Nov 2014 08:38:38 -0700
schrieb Kurt Seifried <kseifried () redhat com>:

The most important part of all: who's going to interpret the fuzzing
results and then co-ordinate with upstreams to make source code fixes?

Well, the answer to that is: the people who do the fuzzing.

My main aim is to make more transparent what's already going on. That's
not going to change who does the fuzzing and how it gets reported.

There lays deeper a question that I asked myself already: What's an
"okay" way of reporting these things?
Basically what I usually did is just sending crash samples to upstream
devs and add some valgrind/asan output. One could argue that I'm
offloading the real work to the upstream devs, however I feel they know
their code better than I do (and often I'm just not qualified to create
the fix). Until now I feel most upstreams were okay with that.


-- 
Hanno Böck
http://hboeck.de/

mail/jabber: hanno () hboeck de
GPG: BBB51E42

Attachment: signature.asc
Description:


Current thread: