Activity for Hanno Böck

  • Hanno Böck Hanno Böck posted a comment on ticket #649

    It's not an online scanner, it's scanning offline on the filesystem. I can test that even without an installation. The only issue here is that I have a database with information of the form "app X had its last security vuln Y that was fixed in Z". It seems right now there is no fixed version, so that's what I'm reporting. I can update it once you make a new release. See here how the data looks: https://git.schokokeks.org/freewvs.git/blob/master/freewvsdb/wiki.json

  • Hanno Böck Hanno Böck posted a comment on ticket #649

    I'm not running phpwiki myself, I'm developing a tool that scans for vulnerable web applications [1]. [1] https://source.schokokeks.org/freewvs/

  • Hanno Böck Hanno Böck created ticket #472

    Cross Site Scripting vulnerability

  • Hanno Böck Hanno Böck created ticket #649

    Security vulnerabilities described on exploit-db

  • Hanno Böck Hanno Böck created ticket #125

    pam_mount uses deprecated openssl 1.1 features

  • Hanno Böck Hanno Böck posted a comment on ticket #890

    Can I ask what the fix is? Your comment indicates this is an underlying thunderbird issue and can't be fixed within Enigmail.

  • Hanno Böck Hanno Böck modified a comment on ticket #2831

    I created a patch that fixes all those issues and a few more. Appart from the ones you mentioned it is also possible to achieve XSS via the formaction attribute or via svg animations (animate to attribute). I'm now adding a lot more filtering, but I believe this doesn't break any common html mails, as other webmailers apply similar filtering. I'm completely removing inline SVG (gmail does the same, so I don't think anyone uses them). Some of the filtering is now redundant, but it may help kill further...

  • Hanno Böck Hanno Böck posted a comment on ticket #2831

    I created a patch that fixes all those issues and a few more. Appart from the ones you mentioned it is also possible to achieve XSS via the formaction attribute or via svg animations (animate to attribute). I'm now adding a lot more filtering, but I believe this doesn't break any common html mails, as other webmailers apply similar filtering. I'm completely removing inline SVG (gmail does the same, so I don't think anyone uses them). Some of the filtering is now redundant, but it may help kill further...

  • Hanno Böck Hanno Böck posted a comment on ticket #39

    asan stack trace

  • Hanno Böck Hanno Böck created ticket #39

    netstat IPv6 handling causes overlapping memcpy

  • Hanno Böck Hanno Böck posted a comment on ticket #16

    I guess nobody is developing here any more, but for completeness I'm attaching a sample address sanitizer stack trace. This can be tested by compiling espeak with asan (make CXXFLAGS="-fsanitize=address -g" LDFLAGS="-fsanitize=address") and then simply running "espeak a".

  • Hanno Böck Hanno Böck created ticket #468

    Mixed content warning on https version of dosbox page

  • Hanno Böck Hanno Böck created ticket #57

    out of bounds heap read in dirac::VHFilter::Interleave

  • Hanno Böck Hanno Böck posted a comment on ticket #56

    example file attached

  • Hanno Böck Hanno Böck created ticket #56

    heap overflow (write) in dirac::ArithCodecBase::ReadAllData

  • Hanno Böck Hanno Böck created ticket #252

    heap out of bounds read in convert_latin1

  • Hanno Böck Hanno Böck created ticket #1026

    duplicate definition of _tab_page_modules

  • Hanno Böck Hanno Böck created ticket #535

    [lxtask] fix multiple definitions of global variables (builds with -fno-common)

  • Hanno Böck Hanno Böck created ticket #116

    compilation with openssl 1.1 fails

  • Hanno Böck Hanno Böck created ticket #185

    null pointer access / segfault in NArchive::N7z::CInArchive::ReadAndDecodePackedStreams

  • Hanno Böck Hanno Böck created ticket #184

    null pointer access / segfault after failing memory allocation in 7zIn.cpp

  • Hanno Böck Hanno Böck posted a comment on ticket #183

    Can confirm fix. I think this bug report can now go public, can you change the "Private"...

  • Hanno Böck Hanno Böck created ticket #174

    fix delete instead of delete [] in encrypt.h

  • Hanno Böck Hanno Böck created ticket #173

    fix buffer overflow in SoftRasterInit

  • Hanno Böck Hanno Böck created ticket #172

    fix gcc compiler warning about pointer conversion in path.h

  • Hanno Böck Hanno Böck created ticket #183

    heap out of bounds read in NArchive::N7z::CDecoder::Decode on malformed input

  • Hanno Böck Hanno Böck created ticket #182

    segfault / null pointer access on malformed input file

  • Hanno Böck Hanno Böck created ticket #34

    errors in tests regarding string length

  • Hanno Böck Hanno Böck posted a comment on ticket #79

    Tested again with latest git code, no change. bug still there.

  • Hanno Böck Hanno Böck posted a comment on ticket #79

    How have you tried to reproduce it? (I wrote that this can be seen with valgrind...

  • Hanno Böck Hanno Böck posted a comment on ticket #79

    I don't see a fix for this, this is still happening in the current git head code....

  • Hanno Böck Hanno Böck created ticket #79

    Invalid heap read in gif2rgb, function DumpScreen2RGB()

  • Hanno Böck Hanno Böck created ticket #78

    Invalid write (heap overflow) in gif2rgb with images of size 0

  • Hanno Böck Hanno Böck created ticket #16

    Avoid negative array access in dictionary.cpp

  • Hanno Böck Hanno Böck created ticket #5

    missing include in read.cpp

  • Hanno Böck Hanno Böck posted a comment on ticket #62

    Hi, just reviewing old issues. The bug here is in the file getarg.c. The command...

  • Hanno Böck Hanno Böck posted a comment on ticket #65

    I'm just reviewing old issues I reported, this was closed without a comment, but...

  • Hanno Böck Hanno Böck created ticket #4

    stack overflow / endless recursion on malformed input

  • Hanno Böck Hanno Böck posted a comment on ticket #3

    I re-found this bug while fuzzing cramfsck, your fix works. Unfortunately it seems...

  • Hanno Böck Hanno Böck created ticket #523

    [lxterminal] Return value on non-void function

  • Hanno Böck Hanno Böck posted a comment on ticket #363

    I had tested the latest release (5.8) but now I see this is quite old. However the...

  • Hanno Böck Hanno Böck created ticket #363

    Invalid C input file causes invalid read / heap overflow

  • Hanno Böck Hanno Böck created ticket #6

    heap overflow / off by one read with malformed arc file

  • Hanno Böck Hanno Böck posted a comment on ticket #82

    Just fyi, libarchive supports rar files (and a ton of other file formats), is free...

  • Hanno Böck Hanno Böck created ticket #65

    segfault in giftool on malformed input file

  • Hanno Böck Hanno Böck created ticket #64

    malformed gif causes crash in giftool

  • Hanno Böck Hanno Böck created ticket #63

    malformed gif causes segfault in giffilter

  • Hanno Böck Hanno Böck created ticket #62

    invalid memory access in most command line tools in util

  • Hanno Böck Hanno Böck created ticket #3

    malformed input causes endless loop

  • Hanno Böck Hanno Böck posted a comment on ticket #421

    Probably something like this: a) export AFL_HARDEN=1; export AFL_USE_ASAN=1 b) compiled...

  • Hanno Böck Hanno Böck posted a comment on ticket #421

    An upper bound for the comments doesn't seem like a clean solution There's something...

  • Hanno Böck Hanno Böck posted a comment on ticket #421

    This was my fuzzing input

  • Hanno Böck Hanno Böck created ticket #421

    malformed .flac file causes crash / segfault

  • Hanno Böck Hanno Böck created ticket #1404

    Secure ZIP encryption should be default, warn about or disable insecure encryption

1