[Python-modules-team] Fuzzing enzyme

Henri Salo henri at nerv.fi
Sat Mar 14 10:02:38 UTC 2015


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Hi,

I found several issues while fuzzing enzyme. I am planning to report these
issues to Github upstream project. Do you want to get notified about created
issues and do you want me to create Debian BTS items about these cases also?

Most of these are probably not security related as it is userland cli tool crash
and not e.g. CWE-400 <https://scapsync.com/cwe/CWE-400> type of denial of
service issue.

Used tools:
  http://lcamtuf.coredump.cx/afl/
  https://bitbucket.org/jwilk/python-afl

In case you need more information or you want me to fuzz other Python tools
please reply, thanks!

- -- 
Henri Salo
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iQIcBAEBAgAGBQJVBAc9AAoJECet96ROqnV0woYP/AroE6j4cGJR8qESVcRoCu/S
t8f4vcSBy20b4dmIRZ45za2ID/sBFKIFqL/vjYO3aHDnbDOOgxXnMPOrmZaxSzfT
KH9fUiX49mdkvsDa6O7bRHt1pSKCuf68jl0aw5LS51TNOtm5XLblg5E4MluH9zWP
d0RY1tQtJ8JS0BGe94ZxQx+IK7mf89HxR1NUxb86UhjctVWInah4PFHkKFSpdGpq
vdg5UgoY0PFqRK+atTUZKqGrEjMBSlSmItsQQt65B8gFP5CKRWzVDiGqMNSDuYwb
OmCSU/QuaKmhqP7QmUJX20EbKips6qNJqZ3Dh1GdI4X0umyO2o5+cNSAcraZPtUI
jqS53pOtHnasemXYBr93YvwsYQ2yUBK3GapjOKVHjtVbrm+luqQwGvLTOHXYuw0J
xwcvgNsDd3qK0DR2Ruu/BDsrXL1K3Cd2OJYhAPl9pvB52on2E5LMSu2Q6R3IK715
YNXlgwlYtLcnNe8XjJgBgr+I5xbh5VULWNmV2J3q/3Hzw37egowL3QhyffZJ1i+e
Y9MExH0yFvJStN3Dua+s7Po4gYgX3mXYciUlUaC3FMJ79mAeajCJG5beCwtN3sl0
AzkL9T6HY+jAC7UH11dv5lOMk7rboQ4npgMsbBEPH7uR1V/DmudHoVVefY4MaUab
iL6JEVGi6Wd4xOtSiQsS
=Q1AO
-----END PGP SIGNATURE-----



More information about the Python-modules-team mailing list