Skip to content
This repository has been archived by the owner on Oct 29, 2022. It is now read-only.

OSS-Fuzz finds a command injection bug in TinyGLTF #108

Closed
1 task done
jonafato opened this issue Sep 9, 2022 · 0 comments
Closed
1 task done

OSS-Fuzz finds a command injection bug in TinyGLTF #108

jonafato opened this issue Sep 9, 2022 · 0 comments
Labels
Content Topics for discussion and inclusion in newsletters

Comments

@jonafato
Copy link
Collaborator

jonafato commented Sep 9, 2022

URL

https://security.googleblog.com/2022/09/fuzzing-beyond-memory-corruption.html

When was this post released

20220908

Summary

OSS-Fuzz, Google's service for fuzz-testing open source software, has identified a command injection vulnerability in TinyGLTF, which has since been patched. OSS-Fuzz has been operating since 2016 and began adding new "sanitizers" in December, 2021, one of which detected the bug in question. The project is accepting new sanitizers and offering rewards of $11,337 for integrations that identify two or more vulnerabilities in existing OSS-Fuzz projects. OSS-Fuzz supports projects written in several programming languages, including Python

Code of Conduct

  • I agree to follow this project's Code of Conduct
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
Content Topics for discussion and inclusion in newsletters
Projects
No open projects
Status: Done
Development

No branches or pull requests

2 participants