This repository has been archived by the owner on Oct 29, 2022. It is now read-only.
OSS-Fuzz finds a command injection bug in TinyGLTF #108
Labels
Content
Topics for discussion and inclusion in newsletters
URL
https://security.googleblog.com/2022/09/fuzzing-beyond-memory-corruption.html
When was this post released
20220908
Summary
OSS-Fuzz, Google's service for fuzz-testing open source software, has identified a command injection vulnerability in TinyGLTF, which has since been patched. OSS-Fuzz has been operating since 2016 and began adding new "sanitizers" in December, 2021, one of which detected the bug in question. The project is accepting new sanitizers and offering rewards of $11,337 for integrations that identify two or more vulnerabilities in existing OSS-Fuzz projects. OSS-Fuzz supports projects written in several programming languages, including Python
Code of Conduct
The text was updated successfully, but these errors were encountered: