Bugs that survive the heat of continuous fuzzing
ID: c3e81b58-2907-5dfa-b3af-086497146f0e
STIX ID: report--c3e81b58-2907-5dfa-b3af-086497146f0e
Feed Name: GitHub Security Lab
This blog post examines why long-running continuous fuzzing (via OSS-Fuzz) still misses serious bugs, illustrating with three case studies—GStreamer (29 vulnerabilities), Poppler (including a 1‑click RCE in Evince), and Exiv2 (multiple CVEs). It identifies causes such as low fuzzer coverage, unfuzzed dependencies, lack of encoder testing, and bugs requiring large or long-running inputs, and presents a five-step workflow (preparation, coverage, context, value, triaging) and advanced techniques to improve fuzzing effectiveness.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
