Twitter | Pretraživanje | |
Pretraživanje Osvježi
David Neto 26. kol
Ok, rewind to early 2017. My team was going to write a SPIR-V backend to DXC, lovingly called Spiregg . Question was: how were we going to test it?
Reply Retweet Označi sa "sviđa mi se"
Kurt Schwehr 11. svi 2018.
GDAL 2.3.0 released! Sadly, I didn't get to test the release candidates (newborn human in the house) has been crazy productive and this... "More than 1000 fixes for issues/vulnerabilities found by OSS-Fuzz"
Reply Retweet Označi sa "sviđa mi se"
Even Rouault 14. tra 2018.
Woo, the 1000th bug against has just been filed ! (actually a bit less since a few ones were actually in other dependant libraries). 977 of them have been fixed. Most remaining ones are unreproducible
Reply Retweet Označi sa "sviđa mi se"
László Szekeres 15. srp
Fuzz Driver Generation at Scale! Check out the preprint of our paper at: work w/ D. Babic, , Y. Chen, , T. King, M. Kusano, , W. Wang. See you at in August!
Reply Retweet Označi sa "sviđa mi se"
Franjo Ivancic 30. kol
I am really proud of my team for receiving a best paper award at ! Check it out at . We synthesize drivers that find security and reliability issues using fuzzing. Many run in - supported with integration rewards
Reply Retweet Označi sa "sviđa mi se"
Edward Hervey (bilboed@bilboed.tech on fediverse) 30. lis 2017.
Finally got integrated into 🤘 and interesting bugs from 2003 code are popping up :)
Reply Retweet Označi sa "sviđa mi se"
Kurt Schwehr 17. pro 2017.
has so far been > 14% of the bugs. Measured by 675 commits crediting OSS Fuzz and OSS Fuzz being at about bug 4672. Credit to for bug fixing!
Reply Retweet Označi sa "sviđa mi se"
Even Rouault 12. kol
is now fuzzing GDAL on i386 and has already found a few 32-bit specific (or generic but easier to spot) bugs
Reply Retweet Označi sa "sviđa mi se"
Even Rouault 6. tra 2018.
creativity makes me discover features of GDAL I was unaware of. For example "ogr2ogr myoutputdatasource myinputdatasourcewithseverallayers -nln somename" will 'merge' all the input layers into a single one (for drivers that support adding fields to non empty layers)
Reply Retweet Označi sa "sviđa mi se"
catenacyber 23. svi
Sharing bounty with ... Help would now be appreciated for merging it with latest
Reply Retweet Označi sa "sviđa mi se"
Jonathan Foote 7. sij 2018.
As of last week is integrated with public . Already found and fixed multiple bugs. Thanks Daniel Salzman and (and ) for your support and prompt attention! /cc .
Reply Retweet Označi sa "sviđa mi se"
Even Rouault 30. ožu 2018.
Ironically the fuzzer for ogr2ogr I wrote to find bugs in the writing part of drivers also helps finding bugs in the reading part :-)
Reply Retweet Označi sa "sviđa mi se"
Semmle 24. lip
Who analyses an OSS project’s security over time? Check out these 4 open security examples that are raising the bar -
Reply Retweet Označi sa "sviđa mi se"
Even Rouault 27. lip 2017.
I'm crediting in ticket commits for bugs it discovered in ... fuzzers I wrote for it...
Reply Retweet Označi sa "sviđa mi se"
Victor (vitaut) Zverovich 30. lip
oss-fuzz integration has been merged into {fmt}: Thanks to !
Reply Retweet Označi sa "sviđa mi se"
Even Rouault 19. lis
Discovering from Bas email that someone has taken care of registering a CVE at least for one of the GDAL issues: . Why this one and not others is a mystery :-)
Reply Retweet Označi sa "sviđa mi se"
Even Rouault 21. svi 2017.
In 11 days of use of on , we have pushed 151 related commits in trunk. Impressive technology ! Hope things will calm down now
Reply Retweet Označi sa "sviđa mi se"
Even Rouault 9. lip 2017.
Crazy that this UK/Ordnance Survey NTF vector format, that no one no longer uses, generates so many bug reports.
Reply Retweet Označi sa "sviđa mi se"
N. Mavrogiannopoulos 22. tra 2017.
Proposed inclusion in . Hoping for the best.
Reply Retweet Označi sa "sviđa mi se"
David Neto 26. kol
Odgovor korisniku/ci @dneto1969
Ok, first fix of a fuzzer bug is: When parsing the checks string, there are cases where a string intended as a regexp isn't a valid RE2 regexp. The fix is to check those cases and fail early. Prevents a heap-buffer-overflow later on
Reply Retweet Označi sa "sviđa mi se"