Loading HuntDB...

Heap-Buffer-Overread in contains_whitespace when calling parser_validate after supplying a maliciously crafted buffer to parser_parse

C
Cosmos
Submitted None

Team Summary

Official summary from Cosmos

A fuzz crash case was discovered, resulting in a `heap-buffer-overread` in the `contains_whitespace` function. This crash was not exploitable in the primary use case of the library, however a length check was added to prevent this case from triggering. This report was awarded a one-time bounty as it was the first valid submission for this target. Future crashes will need to be exploitable to be eligible for bounties for this component going forward.

Reported by l33thaxor

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Bounty

$2000.00

Submitted

Weakness

Buffer Over-read