cURL audit: How a joke led to significant findings
blog.trailofbits.com | blog | #vulnerability-research | #fuzzing | #memory-corruption | #curl | #trail-of-bits | #libcurl | #afl-plus-plus
Summary
Trail of Bits' 2022 cURL audit fuzzed the CLI with AFL++, uncovering CVE-2022-42915 and CVE-2022-43552 plus use-after-free and memory-leak bugs fixed in cURL 7.86.0/7.87.0.
- Published
- Collected
Skip to content