Menu

#363 Invalid C input file causes invalid read / heap overflow

open
nobody
None
5
2015-05-20
2015-05-07
Hanno Böck
No

Attached c file will generate a heap overflow in ctags.
To see this run ctags either compiled with address santiizer or through valgrind.

(this was found with the tool american fuzzy lop)

2 Attachments

Discussion

  • Masatake YAMATO

    Masatake YAMATO - 2015-05-12

    As far as trying https://github.com/fishman/ctags with the input, valgrind says nothing.

     
  • Hanno Böck

    Hanno Böck - 2015-05-19

    I had tested the latest release (5.8) but now I see this is quite old. However the webpage still lists the release. If it is considered deprecated and only the git code is supported then this should be stated somewhere.

     

Log in to post a comment.