Re: [PHP-DEV] PHP on OSS-fuzz

2019-06-20 Thread Stanislav Malyshev
Hi! > Where are issues detected by oss-fuzz reported? Right now on https://oss-fuzz.com/testcases and I copy it to bugs.php.net. It should also send the email when one comes up, but I am not sure whether it goes to security@ too. Also the issues are on https://bugs.chromium.org/p/oss-fuzz/issues/

Re: [PHP-DEV] PHP on OSS-fuzz

2019-06-20 Thread Christoph M. Becker
On 20.06.2019 at 17:54, Nikita Popov wrote: > On Sun, Mar 17, 2019 at 10:23 PM Stanislav Malyshev > wrote: > >> Hi! >> >> Looking at the recent PHP security issues, it is clear that many of them >> are stemming from corner cases in various format-parsing code, and most >> of them either is or can

Re: [PHP-DEV] PHP on OSS-fuzz

2019-06-20 Thread Nikita Popov
On Sun, Mar 17, 2019 at 10:23 PM Stanislav Malyshev wrote: > Hi! > > Looking at the recent PHP security issues, it is clear that many of them > are stemming from corner cases in various format-parsing code, and most > of them either is or can be found by fuzzers. > > Thus, I've made an initial in

Re: [PHP-DEV] PHP on OSS-fuzz

2019-03-21 Thread Michael Wallner
Hey! On 17/03/2019 22:23, Stanislav Malyshev wrote: > Hi! > > Looking at the recent PHP security issues, it is clear that many of them > are stemming from corner cases in various format-parsing code, and most > of them either is or can be found by fuzzers. > > Thus, I've made an initial integrat

[PHP-DEV] PHP on OSS-fuzz

2019-03-17 Thread Stanislav Malyshev
Hi! Looking at the recent PHP security issues, it is clear that many of them are stemming from corner cases in various format-parsing code, and most of them either is or can be found by fuzzers. Thus, I've made an initial integration for PHP on OSS-fuzz project - a fuzzing engine for testing open