-
Notifications
You must be signed in to change notification settings - Fork 228
New issue
Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? # to your account
Stackoverflow CVE-2022-40151 #314
Comments
There seems to be some recursion possible in
Snippet of the stacktrace of using the crashing input:
|
@henryrneh: Thanks for providing the test case here, you did not attach it sending the private mail to me. |
another vulnerability also reported: https://nvd.nist.gov/vuln/detail/CVE-2022-40152 |
This report is simply rubbish! #304 |
CVE-2022-40152 is not directly related to stream: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-40152. |
Thanks for the link, now I get the full picture. @joehni @cesarhernandezgt |
Dear xstream maintainers and users,
the following zip contains crashing input, stacktrace, the fuzz target and all the information needed to reproduce CVE-2022-40151.
Please have a look and contact us if you need more information, thanks.
47367.zip
The text was updated successfully, but these errors were encountered: