Skip to content

Crash test cases discovered with the AFL fuzzer#33

Open
voetsjoeba wants to merge 11 commits intosteveire:masterfrom
voetsjoeba:afl-fuzz-01
Open

Crash test cases discovered with the AFL fuzzer#33
voetsjoeba wants to merge 11 commits intosteveire:masterfrom
voetsjoeba:afl-fuzz-01

Conversation

@voetsjoeba
Copy link
Copy Markdown

As part of an evaluation I'm running to use the Grantlee libraries as a replacement for another more basic templating engine in another (unrelated) project, I took the liberty of running the excellent AFL fuzzer against the Grantlee_Templates library.

This pull request contains test cases reproducing the various crashes that were found. I have additional commits locally that resolve each test case, although I'm not including them here -- I'd prefer to defer those to you since my familiarity with the code base is limited. Most of these have straightforward fixes -- the exception is the PCRE stack overflow on large quoted strings, for which I see no easy fix.

vmuser added 11 commits March 17, 2017 02:20
… Qt due to an at(0) call on an empty QString
…ent at rand() % 0, generating a CPU arithmetic exception
…ailure due to invalid character offset access in string
…ent causes a crash due to an attempt to access a list item at a non-existent position
…ion due to excessive memory allocation attempt in left/right string justify routines
…riable list is empty and the 'reversed' keyword is given
… PCRE library (libpcre16.so.3.13.2 on Ubuntu Xenial 16.04.2 LTS; PCRE 8.38)
@steveire
Copy link
Copy Markdown
Owner

This is great, thanks!

I started pushing fixes together with the tests, but I didn't get through the entire branch yet. I'll continue later.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants