Uploaded image for project: 'Apache Arrow'
  1. Apache Arrow
  2. ARROW-6270

[C++][Fuzzing] IPC reads do not check buffer indices

    XMLWordPrintableJSON

Details

    Description

      The attached crash was found by arrow-ipc-fuzzing-test and indicates that the IPC reader is not checking the flatbuffer encoded buffers for length and can produce out-of-bounds-reads.

      Attachments

        Issue Links

          Activity

            People

              marco.neumann.by Marco Neumann
              marco.neumann.by Marco Neumann
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved:

                Time Tracking

                  Estimated:
                  Original Estimate - Not Specified
                  Not Specified
                  Remaining:
                  Remaining Estimate - 0h
                  0h
                  Logged:
                  Time Spent - 50m
                  50m