Re: Heap-based buffer overflow in the srcnext() function
Frederic Cambus <[email protected]> Sat, 21 Dec 2019 11:21:45 +0100
| Newsgroups | gmane.comp.type-setting.lout |
|---|---|
| Message-ID | <[email protected]> |
On Fri, Dec 20, 2019 at 07:00:59PM +0100, Frederic Cambus wrote: > While fuzzing lout 3.40 with Honggfuzz, I found a heap-based buffer > overflow in the srcnext() function, in z02.c. This issue has been assigned CVE-2019-19918. https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19918