Fuzzing for cups-filters could have higher coverage with low effort
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 5/5
- Thời gian dự kiến
- Hơn một tuần
- Mức phù hợp với người mới
- 35/100
Hướng nghiên cứu
Bắt đầu bằng cách xem xét các dự án cups-filters và libcupsfilters hiện có trong fuzzing/projects, sau đó kiểm tra cupsfilters/filter.h và các Containerfiles Podman hiện có. Công việc hoàn tất khi các fuzzer chấp nhận các tệp phương tiện thô, sử dụng các đầu vào crash thông thường và trong lịch sử làm seed, đồng thời thực thi các công cụ cups-filters hoặc các hàm cfFilter* được yêu cầu.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
Hello @fish98!
I hear that OpenPrinting is soon hosting Winter-of-Code participants again, maybe it is the right time to pitch this:
CUPS-Filters does a lot of media parsing, and media parsing code is diverse and sometimes complicated.
I think it would be good to fuzz it like this:
- Make the fuzzer generate the raw media files as input for the cups-filters tools (or the
cfFilter*functions fromfilter.h). - For seeding the fuzzer with good starting points, normal media files can be used, and ideally also a variety of crash inputs from past bugs and vulnerabilities.
I am raising this because I noticed that the existing fuzzers for cups-filters and libcupsfilters only exercise a small subset of the functionality of these libraries (PDF output helpers and dithering utilities, to be precise). You do not need to have individual fuzzers for these - If the exercised helpers are also used by any of the CUPS-filters tools, it is enough to give an input seed file to the fuzzer which reaches this code, and a modern coverage-guided fuzzer is then able to exercise it.
(P.S., I am unfortunately short on time to do anything on this myself, but I have some Podman Containerfiles that can serve as a starting point to make the cups-filters projects build again. (Although I remember I had trouble linking it statically.) I can happily share that over email if you are interested. Let me know.)
- Ngôn ngữ chính
- C
- Star
- 8
- Fork
- 18
- Chỉ số merge pull request
- Không có pull request nào được merge trong 30 ngày
Chuẩn bị môi trường
Dự án này không cung cấp dev container, Dockerfile hay hướng dẫn đóng góp, nên bạn cần tự thiết lập môi trường: hãy bắt đầu từ README và xem hướng dẫn đóng góp lần đầu của chúng tôi để biết các bước chung.
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của OpenPrinting/fuzzing
-
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 75/100
OpenPrinting/fuzzing#45 ·
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 52/100
OpenPrinting/fuzzing#46 ·
-
Memory allocation/deallocation mismatch in fuzz_array.c causes immediate crash with AddressSanitizerĐang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 55/100
OpenPrinting/fuzzing#43 ·
-
Memory leak in cups `fuzz_ppd` harnessCó thể đã có người làm Có pull request liên kết đang mở hoặc đã được merge. Đang mởbug good first issue
Độ khó 3/5 1-2 ngày Mức phù hợp với người mới 35/100
OpenPrinting/fuzzing#7 ·
-
Failed coverage building for cups-filtersCó thể đã có người làm Có pull request liên kết đang mở hoặc đã được merge. Đang mởgood first issue
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 35/100
OpenPrinting/fuzzing#5 · 1 bình luận ·
Tất cả issue của OpenPrinting/fuzzing
Issue tương tự
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
libsdl-org/SDL#16444 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
bug Component component: net
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 90/100
RT-Thread/rt-thread#11852 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 68/100
MiSTer-devel/ao486_MiSTer#243 ·
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 66/100
siderolabs/pkgs#1710 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
Maintainer thường phản hồi trong vòng 1 ngày