chakra-core / chakra-core/ChakraCore
Reportings bugs found by OSS-Fuzz
- Dominant language
- JavaScript
- Stars
- 9.3k
- Forks
- 1.2k
- PR merge metrics
- No merged PRs in 30d
Description
Hi, we recently started fuzzing Chakra using [OSS-Fuzz](https://github.com/google/oss-fuzz) (google/oss-fuzz#925), and have discovered a number of crashes. Some of them are potentially security vulnerabilities (buffer overflows, bad address dereferences etc).
We'd like to report these bugs by asking Chakra developers/maintainers to send a PR to add their emails (needs to be associated with a [Google account](https://github.com/google/oss-fuzz/blob/master/docs/faq.md#why-do-you-require-a-google-account-for-authentication)) to [this file](https://github.com/google/oss-fuzz/blob/master/projects/chakra/project.yaml) ([example](https://github.com/google/oss-fuzz/blob/master/projects/freetype2/project.yaml)) so that you are CC'ed on current and future bug reports in our issue tracker ([disclosure policy](https://github.com/google/oss-fuzz#bug-disclosure-guidelines)).
Our infrastructure comes with regression range testing, fix verification, de-duplication, testcase minimization, and more.
Thanks!
Contributor guide
Assessment
This issue has not been assessed yet.