Skip to content

Reader/(Writer?) vulnerabilities #163

Description

@Nul-led

Found by Altanis

  • You can cause the undefined behavior when reading unsigned integers due to buffer overflow when the received buffer is too short. We should check for EOF before reading.
  • Apparently you can force vu to return -1 somehow, he didnt elaborate how though.
  • StringNT can also be forced to "look back in forth through the buffer" in some way.

Apparently none of these cause crashes but may or may not lead to UB.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    criticalHigh relevance vulnerabilities that can cause harm to the server or its clients

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions