@taviso somewhat surprising ghostscript seems pretty resistant to fuzzing, not crashing easily
-
-
Hmmm, maybe I'll have to check the latest git version, as opposed to what is provided by Ubuntu.pic.twitter.com/miOnfcmIcm
1 reply 0 retweets 0 likes -
Yes, Ubuntu's is very old -
@hanno says git master is more resistant to fuzzing. They switched licenses though, it's a mess3 replies 0 retweets 1 like -
Ah, it looks like 3/4 of the crashes found with the Ubuntu version are fixed in the git version of ghostscript.
1 reply 0 retweets 0 likes -
2 hours into a single-vm fuzzing campaign against the latest git version of ghostscript.pic.twitter.com/kh1P7gP6id
2 replies 0 retweets 1 like -
Please fuzz with -dSAFER, probably still works, but without -dSAFER .ps can just run shell commands!
2 replies 0 retweets 1 like
Good to know! I only put together cmdline based on some half-assed web searching. And yeah they still crash with -dSAFER.
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.