Fuzzing for cups-filters could have higher coverage with low effort
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 5/5
- Tempo stimato
- Più di una settimana
- Idoneità per principianti
- 35/100
Direzione di ricerca
Inizia esaminando i progetti cups-filters e libcupsfilters esistenti in fuzzing/projects, quindi ispeziona cupsfilters/filter.h e i Containerfiles Podman disponibili. Il lavoro è completo quando i fuzzers accettano file multimediali grezzi, usano come seeds input di crash normali e storici ed esercitano gli strumenti cups-filters o le funzioni cfFilter* richieste.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Hello @fish98!
I hear that OpenPrinting is soon hosting Winter-of-Code participants again, maybe it is the right time to pitch this:
CUPS-Filters does a lot of media parsing, and media parsing code is diverse and sometimes complicated.
I think it would be good to fuzz it like this:
- Make the fuzzer generate the raw media files as input for the cups-filters tools (or the
cfFilter*functions fromfilter.h). - For seeding the fuzzer with good starting points, normal media files can be used, and ideally also a variety of crash inputs from past bugs and vulnerabilities.
I am raising this because I noticed that the existing fuzzers for cups-filters and libcupsfilters only exercise a small subset of the functionality of these libraries (PDF output helpers and dithering utilities, to be precise). You do not need to have individual fuzzers for these - If the exercised helpers are also used by any of the CUPS-filters tools, it is enough to give an input seed file to the fuzzer which reaches this code, and a modern coverage-guided fuzzer is then able to exercise it.
(P.S., I am unfortunately short on time to do anything on this myself, but I have some Podman Containerfiles that can serve as a starting point to make the cups-filters projects build again. (Although I remember I had trouble linking it statically.) I can happily share that over email if you are interested. Let me know.)
- Lingua principale
- C
- Stelle
- 8
- Fork
- 18
- Merge medio
- 7h 37m
- PR unite (30g)
- 1
Guida per i contributori
Nessuna guida per i contributori indicizzata per questo repository
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di OpenPrinting/fuzzing
-
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 75/100
OpenPrinting/fuzzing#45 ·
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 52/100
OpenPrinting/fuzzing#46 ·
-
Memory allocation/deallocation mismatch in fuzz_array.c causes immediate crash with AddressSanitizer Aperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 55/100
OpenPrinting/fuzzing#43 ·
-
bug good first issue
Difficoltà 3/5 1-2 giorni Idoneità per principianti 35/100
OpenPrinting/fuzzing#7 ·
-
good first issue
Difficoltà 4/5 3-5 giorni Idoneità per principianti 35/100
OpenPrinting/fuzzing#5 · 1 commento ·
Tutte le issue di OpenPrinting/fuzzing
Issue simili
-
internal.h中,漏掉了1个定义。 Aperta
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 95/100
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 88/100
-
Broadcast Documentation Aperta
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 90/100
kovidgoyal/kitty#10516 ·
-
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 80/100
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
zephyrproject-rtos/zephyr#120011 ·