Heap-Buffer-Overread in contains_whitespace when calling parser_validate after supplying a maliciously crafted buffer to parser_parse
C
Cosmos
Submitted None
Team Summary
Official summary from Cosmos
A fuzz crash case was discovered, resulting in a `heap-buffer-overread` in the `contains_whitespace` function. This crash was not exploitable in the primary use case of the library, however a length check was added to prevent this case from triggering. This report was awarded a one-time bounty as it was the first valid submission for this target. Future crashes will need to be exploitable to be eligible for bounties for this component going forward.
Actions:
Reported by
l33thaxor
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Bounty
$2000.00
Submitted
Weakness
Buffer Over-read