forked from jmckaskill/c-capnproto
-
Notifications
You must be signed in to change notification settings - Fork 42
Open
Description
I strongly believe that there should be a security warning in the README regarding malicious input.
There is currently no code to verify buffers/structures, unless I missed something completely?
I think a small notice like #29 should suffice.
Any program will crash horrendously should it encounter malicious/corrupted input. If anyone is interested, I adjusted the included tests/examples to be used with american fuzzy lop here. You can test with make fuzz-mem and make fuzz-fp.
Metadata
Metadata
Assignees
Labels
No labels