logo

Google Unveils OSS-Fuzz to test Open Source Software Security

ID: f2808b8e-1c26-5b46-b050-1b5d11e53d61

STIX ID: report--f2808b8e-1c26-5b46-b050-1b5d11e53d61

Feed Name: Security Ledger

Threat Score
10/100

Date Published: 2016-12-03

Date Updated: 2026-05-08

Author: Paul Roberts

...
...

Google announced OSS-Fuzz, a continuous, automated fuzzing service that combines fuzzing engines (e.g., libFuzzer) with sanitizers and ClusterFuzz to find bugs in open-source components; the report notes OSS-Fuzz quickly discovered a heap buffer overflow in the FreeType library which was promptly fixed, and positions the service as a means to improve open-source software security and reduce risks such as those exemplified by Heartbleed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.