A fuzzy issue of responsible disclosure
A fuzzy issue of responsible disclosure
Posted Aug 16, 2022 19:24 UTC (Tue) by mcatanzaro (subscriber, #93033)In reply to: A fuzzy issue of responsible disclosure by Wol
Parent article: A fuzzy issue of responsible disclosure
Reporting a legitimate security vulnerability is not harassment. Come on, seriously?
Bug reports from fuzzers are gold standard because they always contain a reproducer and almost always contain output from asan. And almost all fuzzer reports are security vulnerabilities. If it's not remote code execution, then it's denial of service. Crashes in parsers are not benign.
