@taviso somewhat surprising ghostscript seems pretty resistant to fuzzing, not crashing easily
-
-
I googled for some PS commands and did some sed on the html, here: https://paste.pound-python.org/show/ANmbvMZtAuzIgnOjFYuK/ …
2 replies 0 retweets 0 likes -
I dunno, I just generated random commands and it crashes quickly, e.g. try `lock %for_real_continue quit`
1 reply 0 retweets 1 like -
blah, crashes constantly, e.g. `clear .sethalftone5`
1 reply 0 retweets 0 likes -
are you reporting these? With better dictionary I now also can replicate them, but haven't found more
2 replies 0 retweets 1 like -
I filed them, they fixed both within an hour. I think good quality test cases is what was missing from previous reports.
1 reply 0 retweets 1 like -
1 reply 0 retweets 0 likes
looking at the patch, it's probably exploitable because of the missing typecheck e.g. 16#41414141 dup .sethalftone5
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.