Fuzzing for cups-filters could have higher coverage with low effort
まだ誰も着手していません。
評価
調査の方向性
まず fuzzing/projects 配下にある既存の cups-filters プロジェクトと libcupsfilters プロジェクトを確認し、次に cupsfilters/filter.h と利用可能な Podman Containerfiles を調べます。fuzzer が生のメディアファイルを受け付け、通常のクラッシュ入力と過去のクラッシュ入力を seed として使用し、要求された cups-filters ツールまたは cfFilter* 関数を実行できれば、作業は完了です。
索引モデルが issue の本文から書いたものです。
説明
Hello @fish98!
I hear that OpenPrinting is soon hosting Winter-of-Code participants again, maybe it is the right time to pitch this:
CUPS-Filters does a lot of media parsing, and media parsing code is diverse and sometimes complicated.
I think it would be good to fuzz it like this:
- Make the fuzzer generate the raw media files as input for the cups-filters tools (or the
cfFilter*functions fromfilter.h). - For seeding the fuzzer with good starting points, normal media files can be used, and ideally also a variety of crash inputs from past bugs and vulnerabilities.
I am raising this because I noticed that the existing fuzzers for cups-filters and libcupsfilters only exercise a small subset of the functionality of these libraries (PDF output helpers and dithering utilities, to be precise). You do not need to have individual fuzzers for these - If the exercised helpers are also used by any of the CUPS-filters tools, it is enough to give an input seed file to the fuzzer which reaches this code, and a modern coverage-guided fuzzer is then able to exercise it.
(P.S., I am unfortunately short on time to do anything on this myself, but I have some Podman Containerfiles that can serve as a starting point to make the cups-filters projects build again. (Although I remember I had trouble linking it statically.) I can happily share that over email if you are interested. Let me know.)
- 主要言語
- C
- スター
- 8
- フォーク
- 18
- PR マージ指標
- 30日以内にマージされた PR はありません
環境構築
このプロジェクトには開発コンテナ、Dockerfile、コントリビューションガイドがありません。まず README を読み、一般的な手順ははじめてのコントリビューションガイドを参照してください。
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
OpenPrinting/fuzzing のほかの issue
-
難易度 1/5 1時間未満 初心者へのやさしさ 75/100
OpenPrinting/fuzzing#45 ·
-
難易度 2/5 1〜3時間 初心者へのやさしさ 52/100
OpenPrinting/fuzzing#46 ·
-
Memory allocation/deallocation mismatch in fuzz_array.c causes immediate crash with AddressSanitizerオープン
難易度 2/5 1〜3時間 初心者へのやさしさ 55/100
OpenPrinting/fuzzing#43 ·
-
bug good first issue
難易度 3/5 1〜2日 初心者へのやさしさ 35/100
OpenPrinting/fuzzing#7 ·
-
good first issue
難易度 4/5 3〜5日 初心者へのやさしさ 35/100
OpenPrinting/fuzzing#5 · コメント 1 件 ·
OpenPrinting/fuzzing の issue をすべて見る
似ている issue
-
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
BasedHardware/omi#20401 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 76/100
php/frankenphp#2688 ·
メンテナーはふだん 1 日以内に返信
-
area/ysql kind/bug priority/medium
難易度 2/5 1〜3時間 初心者へのやさしさ 86/100
yugabyte/yugabyte-db#34584 ·
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 88/100
メンテナーはふだん 1 日以内に返信
-
bug priority-medium severity-medium
難易度 2/5 1〜3時間 初心者へのやさしさ 84/100
メンテナーはふだん 2 日以内に返信