News Score: Score the News, Sort the News, Rewrite the Headlines

Why CVE-2022-3602 was not detected by fuzz testing

So recently a very hyped memory corruption security vulnerability was discovered in the OpenSSL punycode parser.Some folks including Hanno (https://twitter.com/hanno/status/1587775675397726209) asked why this is still happenning, why no one wrote a fuzzer for the punycode parser and if we as the security community have learned nothing from Heartbleed.I think we should give the developers the benefit of doubt and assume they were acting in good faith and try to see what could be improved.In fact,...

Read more at allsoftwaresucks.blogspot.com

© News Score  score the news, sort the news, rewrite the headlines