Re: [FD] [oss-security] libical 0.47 SEGV on unknown address

2016-07-06 Thread Brandon Perry
I have gone ahead and just pushed my fuzzing results to Github. These were found with American Fuzzy Lop. https://github.com/brandonprry/ical-fuzz While Mozilla lists information leaks as viable for a bug bounty [1], unless it straight up crashes

Re: [FD] [oss-security] libical 0.47 SEGV on unknown address

2016-06-27 Thread Brandon Perry
> On Jun 25, 2016, at 10:34 AM, Alan Coopersmith > wrote: > > On 06/24/16 06:54 AM, Brandon Perry wrote: >> I am posting this to Full Disclosure/OSS instead of reporting it because I >> have >> opened a handful of libical bugs in the Mozilla bug tracker, alerted

Re: [FD] [oss-security] libical 0.47 SEGV on unknown address

2016-06-27 Thread Alan Coopersmith
On 06/24/16 06:54 AM, Brandon Perry wrote: I am posting this to Full Disclosure/OSS instead of reporting it because I have opened a handful of libical bugs in the Mozilla bug tracker, alerted secur...@mozilla.org , and worked to show how and where to reproduce the