Re: american-fuzzy-lop contains exploit samples which trigger ClamAV

2017-11-13 Thread Richard W.M. Jones
On Mon, Nov 13, 2017 at 02:44:14PM +, Sérgio Basto wrote: > On Mon, 2017-11-13 at 14:25 +, Richard W.M. Jones wrote: > > (Thanks to Patrick for bringing this issue to my attention.) > > > > American Fuzzy Lop ("afl", Fedora package american-fuzzy-lop) is an > > instrumentation-driven fuzze

Re: american-fuzzy-lop contains exploit samples which trigger ClamAV

2017-11-13 Thread Sérgio Basto
On Mon, 2017-11-13 at 14:25 +, Richard W.M. Jones wrote: > (Thanks to Patrick for bringing this issue to my attention.) > > American Fuzzy Lop ("afl", Fedora package american-fuzzy-lop) is an > instrumentation-driven fuzzer for binary formats. ClamAV is a > (Windows?) virus scanner. > > Afl'

american-fuzzy-lop contains exploit samples which trigger ClamAV

2017-11-13 Thread Richard W.M. Jones
(Thanks to Patrick for bringing this issue to my attention.) American Fuzzy Lop ("afl", Fedora package american-fuzzy-lop) is an instrumentation-driven fuzzer for binary formats. ClamAV is a (Windows?) virus scanner. Afl's documentation comes with some demonstration vulerabilities found by afl.