Skip to content

clam-1645 fix overread during ldb load#560

Merged
val-ms merged 1 commit intoCisco-Talos:mainfrom
Emzi-Noxum:clam-1645
May 31, 2022
Merged

clam-1645 fix overread during ldb load#560
val-ms merged 1 commit intoCisco-Talos:mainfrom
Emzi-Noxum:clam-1645

Conversation

@Emzi-Noxum
Copy link
Copy Markdown
Contributor

Added bounds checking for 3-byte comparison step

Code defect, not a vuln

@Emzi-Noxum Emzi-Noxum requested review from shutton and val-ms April 22, 2022 18:13
Copy link
Copy Markdown
Contributor

@shutton shutton left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@val-ms
Copy link
Copy Markdown
Contributor

val-ms commented May 17, 2022

Could you also add a merge request to the private fuzz corpus?

Added bounds checking for 3-byte comparison step

Code defect, not a vuln
@val-ms
Copy link
Copy Markdown
Contributor

val-ms commented May 28, 2022

Rebased to see it go through the test pipelines with the PoC in there.

@val-ms val-ms merged commit f7e120a into Cisco-Talos:main May 31, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants