-
Notifications
You must be signed in to change notification settings - Fork 91
Open
Labels
criticalHigh relevance vulnerabilities that can cause harm to the server or its clientsHigh relevance vulnerabilities that can cause harm to the server or its clients
Description
Found by Altanis
- You can cause the undefined behavior when reading unsigned integers due to buffer overflow when the received buffer is too short. We should check for EOF before reading.
- Apparently you can force vu to return -1 somehow, he didnt elaborate how though.
- StringNT can also be forced to "look back in forth through the buffer" in some way.
Apparently none of these cause crashes but may or may not lead to UB.
Metadata
Metadata
Assignees
Labels
criticalHigh relevance vulnerabilities that can cause harm to the server or its clientsHigh relevance vulnerabilities that can cause harm to the server or its clients