Skip to content

multiple heap out of bounds reads in libinjection_xss() #150

@invd

Description

@invd

Mid-June, I discovered and privately reported out of bounds read issues in the XSS detection to @client9, but so far have not received a reply.

The out of bounds reads happen in multiple code positions. In theory, this may lead to information disclosure.
During analysis, one out of bounds read segfault was observed, but this could not be reproduced and is likely an artifact of the testing environment.

@client9: can you give some quick feedback on whether you want the details to be disclosed publicly here in the bugtracker or prefer them to stay nonpublic until the 16.9.2020 (90 days after initial disclosure)?

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions