Salvatore,
This is pretty bare-bones for a CVE.
And it would not have become one if the submitter had coordinated withe upstream project.
It's essentially a false positive.
The crasher happens in the fuzzing scaffolding, not in the library itself.
In this case, a "nice to have" consistency behavior had been added to the fuzzing tests as an assert.
Fixing this made the library better. But this was no segfault that could happen in the wild.
We are working on updating the package to the v1.4.11 upstream release.
That will fix this.
Sysop: | Keyop |
---|---|
Location: | Huddersfield, West Yorkshire, UK |
Users: | 481 |
Nodes: | 16 (2 / 14) |
Uptime: | 12:29:05 |
Calls: | 9,540 |
Calls today: | 8 |
Files: | 13,653 |
Messages: | 6,139,413 |
Posted today: | 1 |