Re: Heap-based buffer overflow in the srcnext() function

Frederic Cambus <[email protected]> Sat, 21 Dec 2019 11:21:45 +0100
Newsgroups gmane.comp.type-setting.lout
Message-ID <[email protected]>
On Fri, Dec 20, 2019 at 07:00:59PM +0100, Frederic Cambus wrote:

> While fuzzing lout 3.40 with Honggfuzz, I found a heap-based buffer
> overflow in the srcnext() function, in z02.c.

This issue has been assigned CVE-2019-19918.

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19918