Fuzzing for cups-filters could have higher coverage with low effort
Nobody has claimed this yet.
Assessment
- Difficulty
- 5/5
- Estimated time
- Over a week
- Newbie friendliness
- 35/100
Research direction
Start by reviewing the existing cups-filters and libcupsfilters projects under fuzzing/projects, then inspect cupsfilters/filter.h and the available Podman Containerfiles. The work is complete when fuzzers accept raw media files, use normal and historical crash inputs as seeds, and exercise the requested cups-filters tools or cfFilter* functions.
Written by the indexing model from the issue text.
Description
Hello @fish98!
I hear that OpenPrinting is soon hosting Winter-of-Code participants again, maybe it is the right time to pitch this:
CUPS-Filters does a lot of media parsing, and media parsing code is diverse and sometimes complicated.
I think it would be good to fuzz it like this:
- Make the fuzzer generate the raw media files as input for the cups-filters tools (or the
cfFilter*functions fromfilter.h). - For seeding the fuzzer with good starting points, normal media files can be used, and ideally also a variety of crash inputs from past bugs and vulnerabilities.
I am raising this because I noticed that the existing fuzzers for cups-filters and libcupsfilters only exercise a small subset of the functionality of these libraries (PDF output helpers and dithering utilities, to be precise). You do not need to have individual fuzzers for these - If the exercised helpers are also used by any of the CUPS-filters tools, it is enough to give an input seed file to the fuzzer which reaches this code, and a modern coverage-guided fuzzer is then able to exercise it.
(P.S., I am unfortunately short on time to do anything on this myself, but I have some Podman Containerfiles that can serve as a starting point to make the cups-filters projects build again. (Although I remember I had trouble linking it statically.) I can happily share that over email if you are interested. Let me know.)
- Dominant language
- C
- Stars
- 8
- Forks
- 18
- Avg merge
- 7h 37m
- Merged PRs (30d)
- 1
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from OpenPrinting/fuzzing
-
Difficulty 1/5 Under an hour Newbie friendliness 75/100
OpenPrinting/fuzzing#45 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 52/100
OpenPrinting/fuzzing#46 ·
-
Memory allocation/deallocation mismatch in fuzz_array.c causes immediate crash with AddressSanitizer Open
Difficulty 2/5 1-3 hours Newbie friendliness 55/100
OpenPrinting/fuzzing#43 ·
-
bug good first issue
Difficulty 3/5 1-2 days Newbie friendliness 35/100
OpenPrinting/fuzzing#7 ·
-
good first issue
Difficulty 4/5 3-5 days Newbie friendliness 35/100
OpenPrinting/fuzzing#5 · 1 comment ·
All issues in OpenPrinting/fuzzing
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
corazawaf/coraza-nginx#140 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
BasedHardware/omi#15662 · 1 comment ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
-
bug
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
-
level/task module/gcp type/bug
Difficulty 2/5 1-3 hours Newbie friendliness 85/100