Vulnerability Discovery in Open Source Libraries Part 1: Tools of the Trade
ID: 55db71c7-d15b-5b06-9cf0-1c0a5214b1b2
STIX ID: report--55db71c7-d15b-5b06-9cf0-1c0a5214b1b2
Feed Name: McAfee Labs Blog
McAfee researchers used AFL-based fuzzing and sanitizers (ASAN/LSAN) to test libEMF, discovering multiple locally-exploitable memory-corruption and resource-leak vulnerabilities (including out-of-bounds access, signed integer overflow, use-after-free, and memory leaks). They triaged crashes, reported five distinct issues (assigned CVE-2020-11863, CVE-2020-11864, CVE-2020-11865, CVE-2020-11866, CVE-2020-13999), and coordinated fixes with the library maintainer, emphasizing the importance of auditing third-party open-source libraries and using compiler sanitizers in development.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
