Closed Bug 1804646 Opened 3 years ago Closed 1 year ago

Add pkcs12 fuzzing target

Categories

(NSS :: Test, enhancement, P2)

x86_64
Linux
enhancement

Tracking

(firefox-esr128 wontfix, firefox133 fixed)

RESOLVED FIXED
Tracking Status
firefox-esr128 --- wontfix
firefox133 --- fixed

People

(Reporter: decoder, Assigned: mdauer)

References

Details

(Keywords: sec-audit, sec-want, Whiteboard: [post-critsmash-triage][adv-main133-])

Attachments

(1 file, 1 obsolete file)

As discussed, NSS lacks a fuzzing target for PKCS12.

Bug should remain hidden until the target is sufficiently tested and all dependencies are resolved.

Depends on: CVE-2023-0767
Depends on: 1804660
Depends on: 1804662
Attachment #9307281 - Attachment is obsolete: true

There's a r+ patch which didn't land and no activity in this bug for 2 weeks.
:decoder, could you have a look please?
If you still have some work to do, you can add an action "Plan Changes" in Phabricator.
For more information, please visit auto_nag documentation.

Flags: needinfo?(jschanck)
Flags: needinfo?(choller)
Flags: needinfo?(choller)

John, can you please check Priority and Severity on this bug and land the patch if ready ? Thanks !

Severity: -- → S3
Priority: -- → P2
Flags: needinfo?(jschanck)

Maurice, if you are interested, feel free to take this bug over and move it forward as you see fit :) We've been getting some requests from people who would like to reproduce bugs found with this, which is how I noticed that we never landed this.

Flags: needinfo?(mdauer)

Sounds intriguing, I will take a look. Thanks!

Flags: needinfo?(mdauer)
Assignee: choller → mdauer
Status: ASSIGNED → RESOLVED
Closed: 1 year ago
Resolution: --- → FIXED
Flags: qe-verify-
Whiteboard: [post-critsmash-triage]
Whiteboard: [post-critsmash-triage] → [post-critsmash-triage][adv-main133-]
Group: core-security-release
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: