Join GitHub today
GitHub is home to over 40 million developers working together to host and review code, manage projects, and build software together.
Sign upoutside bounds access during xml parsing #1844
Comments
This comment has been minimized.
This comment has been minimized.
|
The crashing input was: "<?>\0"but it can probably be minimized more. |
This comment has been minimized.
This comment has been minimized.
|
Thanks for finding this. Don't replace it with |
This comment has been minimized.
This comment has been minimized.
|
Warning: this issue has been inactive for 35 days and will be automatically closed on 2019-09-10 if there is no further activity. If you are waiting for a response but haven't received one it's possible your question is somehow inappropriate. E.g. it is off topic, you didn't follow the issue submission instructions, or your question is easily answerable by reading the FAQ, dlib's official compilation instructions, dlib's API documentation, or a Google search. |
This comment has been minimized.
This comment has been minimized.
|
I guess I will have to spend more than 30 s on the fix :-) |
This comment has been minimized.
This comment has been minimized.
|
Warning: this issue has been inactive for 35 days and will be automatically closed on 2019-10-21 if there is no further activity. If you are waiting for a response but haven't received one it's possible your question is somehow inappropriate. E.g. it is off topic, you didn't follow the issue submission instructions, or your question is easily answerable by reading the FAQ, dlib's official compilation instructions, dlib's API documentation, or a Google search. |
This comment has been minimized.
This comment has been minimized.
|
Warning: this issue has been inactive for 43 days and will be automatically closed on 2019-10-21 if there is no further activity. If you are waiting for a response but haven't received one it's possible your question is somehow inappropriate. E.g. it is off topic, you didn't follow the issue submission instructions, or your question is easily answerable by reading the FAQ, dlib's official compilation instructions, dlib's API documentation, or a Google search. |
This comment has been minimized.
This comment has been minimized.
|
Notice: this issue has been closed because it has been inactive for 45 days. You may reopen this issue if it has been closed in error. |
Fuzzing dlib::xml_parser I found a crash after 177 milliseconds. It's a string access outside bounds in this function
I will submit a pull request with the fix (replacing str[i] with str.at(i)).