Skip to content

Reader/(Writer?) vulnerabilities #163

@Nul-led

Description

@Nul-led

Found by Altanis

  • You can cause the undefined behavior when reading unsigned integers due to buffer overflow when the received buffer is too short. We should check for EOF before reading.
  • Apparently you can force vu to return -1 somehow, he didnt elaborate how though.
  • StringNT can also be forced to "look back in forth through the buffer" in some way.

Apparently none of these cause crashes but may or may not lead to UB.

Metadata

Metadata

Assignees

No one assigned

    Labels

    criticalHigh relevance vulnerabilities that can cause harm to the server or its clients

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions