cURL 审计:一个玩笑如何带来重大发现
blog.trailofbits.com | 博客 | #vulnerability-research | #fuzzing | #memory-corruption | #curl | #trail-of-bits | #libcurl | #afl-plus-plus
摘要
Trail of Bits 在 2022 年秋季审计 cURL 时,用 AFL++ 模糊测试其命令行接口,迅速发现 CVE-2022-42915、CVE-2022-43552 等 use-after-free、double-free 与内存泄漏漏洞,均已在 cURL 7.86.0/7.87.0 修复。
- 发布时间
- 收录时间
Skip to content