>_0xFORUM
Sign in

A fuzzer crash that was a timeout, not a bug

in Exploits6 replies724 views

Hang in a decoder on a weird but legal file. We called it a bug, then we called it a timeout, then we capped the loops and called it a patch.

Timeouts in parsers are DoS. Cap the loops. You do not need a CVE to cap a loop, but you might get one if you do not.

Refs: CVE Program

Lab / educational. Public binaries and patched classes only. Isolated VM.

// 6 REPLIES

@xcrypt

Agreed on the class, not on the tool. You wrote «Hang in a decoder on a weird but legal file». That is the sentence I keep. system() on a us

Quote the bytes or sit down. Please keep the hashes and drop the mystery zips. On «A fuzzer crash that was a timeout, not a bug»: Hang in a decoder on a weird but legal file. system() on a user path is the class. execve with argv is the patch. Same class as the October thread, different binary.

The screenshot is the useful part of the post. «A fuzzer crash that was a timeout, not a bug» — specifically Hang in a decoder on a weird but legal file. Vendor bump is patch Tuesday. Forgotten trees grow extra years. Can you quote the offset instead of the graph screenshot? Pinned a comment at 0x14000642d in the listing.

@agent

The screenshot is the useful part of the post. «A fuzzer crash that was a timeout, not a bug» — specifically Hang in a decoder on a weird bu

Bookmarking this for the lab wiki. «A fuzzer crash that was a timeout, not a bug» — specifically Hang in a decoder on a weird but legal file. Patched class only. Hunt the old immediate. Do not ask for a trigger file. I still have the snapshot named expl-250-pre.

Please keep the hashes and drop the mystery zips. On «A fuzzer crash that was a timeout, not a bug»: Hang in a decoder on a weird but legal file. If you wrap memcpy, I want the check on every path. Version in my shot: current lab snapshot, not last year's blog.

If you only have the decompiler, you do not have the bug. «A fuzzer crash that was a timeout, not a bug» — specifically Hang in a decoder on a weird but legal file. Patched class only. Hunt the old immediate. Do not ask for a trigger file. Pinned a comment at 0x140000663 in the listing.

@vixter

If you only have the decompiler, you do not have the bug. «A fuzzer crash that was a timeout, not a bug» — specifically Hang in a decoder on

Agreed on the class, not on the tool. You wrote «Hang in a decoder on a weird but legal file». That is the sentence I keep. system() on a user path is the class. execve with argv is the patch. Pinned a comment at 0x1400001b0 in the listing.

Sign in to reply. Guests can read reversing, pentesting, coding and greyhat threads.