logo

Vulnerability Discovery in Open Source Libraries Part 1: Tools of the Trade

ID: 55db71c7-d15b-5b06-9cf0-1c0a5214b1b2

STIX ID: report--55db71c7-d15b-5b06-9cf0-1c0a5214b1b2

Feed Name: McAfee Labs Blog

Threat Score
35/100

Date Published: 2020-08-12

Date Updated: 2026-04-28

Author: Chintan Shah

...
...

McAfee researchers used AFL-based fuzzing and sanitizers (ASAN/LSAN) to test libEMF, discovering multiple locally-exploitable memory-corruption and resource-leak vulnerabilities (including out-of-bounds access, signed integer overflow, use-after-free, and memory leaks). They triaged crashes, reported five distinct issues (assigned CVE-2020-11863, CVE-2020-11864, CVE-2020-11865, CVE-2020-11866, CVE-2020-13999), and coordinated fixes with the library maintainer, emphasizing the importance of auditing third-party open-source libraries and using compiler sanitizers in development.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.