Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Domato CVE refs #39

Open
zodiac-zodiac opened this issue Oct 31, 2022 · 3 comments
Open

Domato CVE refs #39

zodiac-zodiac opened this issue Oct 31, 2022 · 3 comments

Comments

@zodiac-zodiac
Copy link

I noticed that the CVEs referred are bit old despite the fact that i was able to discover the recent CVE-2022-3040 with Domato.

I didn't know that this Domato finding was CVE-2022-3040, but when i tired to submit the bug i found a similar crash reported and submitted for the same code few months ago and then it was labeled as CVE-2022-3040 ( i wish i was bit faster :) )

I think we can add this new CVE ref in the readme ?

I can share the Domato output that triggered this crash identified in CVE-2022-3040, this was generated using the default template !

@zodiac-zodiac zodiac-zodiac changed the title domato CVE- Domato CVE refs Oct 31, 2022
@zodiac-zodiac
Copy link
Author

Attached is the Domato output that triggered this crash in CVE-2022-3040

fuzz_3467842.txt
output that triggered this

@ifratric
Copy link
Collaborator

Thanks for letting me know this was findable by Domato.
The Domato CVE list in the README is unmaintained and contains just the bugs I found before Domato or some its featurese were released.

@zodiac-zodiac
Copy link
Author

Perfect, thank you Ivan. I submitted a PR with small text update to refer to this CVE in the README and also attached the original output file in the PR comment if needed (for reproducibility)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants