Remove tag crashes
article thumbnail

CVE-2020-15359: VDALabs Uses Mayhem To Find MP3Gain Stack Overflow

ForAllSecure

During the fuzz test of the MP3Gain utility, VDA Labs discovered nearly 1,600 crash conditions out of over 6,000 test suites. Mayhem condensed these countless crashes into three unique defects, including a stack overflow condition in a local variable. What Was Found. Mayhem provided the location in code for the vulnerability.

Linux 52
article thumbnail

CVE-2020-15359: VDALabs Uses Mayhem To Find MP3Gain Stack Overflow

ForAllSecure

During the fuzz test of the MP3Gain utility, VDA Labs discovered nearly 1,600 crash conditions out of over 6,000 test suites. Mayhem condensed these countless crashes into three unique defects, including a stack overflow condition in a local variable. What Was Found. Mayhem provided the location in code for the vulnerability.

Linux 52
Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

CVE-2020-15359: VDALabs Uses Mayhem To Find MP3Gain Stack Overflow

ForAllSecure

During the fuzz test of the MP3Gain utility, VDA Labs discovered nearly 1,600 crash conditions out of over 6,000 test suites. Mayhem condensed these countless crashes into three unique defects, including a stack overflow condition in a local variable. What Was Found. Mayhem provided the location in code for the vulnerability.

Linux 52
article thumbnail

Tile is selling its Bluetooth tracking business to Life360 for $205 million

The Verge

Tile popularized marking items and tracking them from your phone with its small Bluetooth tags, but is suddenly facing more competition from giants like Apple, Amazon, Google, and Samsung. Life360 bills itself as an overall family safety app, with location sharing between family members, crash detection, and other features.

Apple 111
article thumbnail

Fuzzing the lighttpd Docker Image

ForAllSecure

tagged Docker image and click Next to configure the corresponding Mayhemfile. Crashing Test Cases : 21. Time : The time of the resulting program crash during the Mayhem run. Instructions: Navigate to the Create New Run page. Select the 1.4.15 Scroll down to the Analysis and Test Cases/Defects pane. Runtime Errors : 0.

article thumbnail

Six-Library Vulnerability in NGA

ForAllSecure

Not long after throwing some of these test binaries into Mayhem crashes start pouring out of one of them: six-extract-xml, a binary that (as the name implies) extracts xml data from the satellite data files. Let’s look more in detail at one of these crashes. Don’t stop fuzzing just because you’ve found a bug!

Data 52
article thumbnail

Six-Library Vulnerability in NGA

ForAllSecure

Not long after throwing some of these test binaries into Mayhem crashes start pouring out of one of them: six-extract-xml, a binary that (as the name implies) extracts xml data from the satellite data files. Let’s look more in detail at one of these crashes. Don’t stop fuzzing just because you’ve found a bug!

Data 52