Fix CVE-2023-27390

"Self" message are not supported, but this was not checked. This
triggered the error "Something is wrong", and then caused a buffer
overflow.

Bug:https://github.com/ArthurSonzogni/Diagon/issues/65
This commit is contained in:
ArthurSonzogni
2023-05-04 23:33:48 +02:00
parent a97c42523a
commit 01ac8690d5
9 changed files with 72 additions and 11 deletions
+2 -2
View File
@@ -2,7 +2,7 @@ set(CMAKE_C_COMPILER clang)
set(CMAKE_CXX_COMPILER clang++)
add_executable(fuzzer src/fuzzer.cpp)
target_compile_options(fuzzer PRIVATE -fsanitize=fuzzer,address)
target_link_libraries(fuzzer PRIVATE -fsanitize=fuzzer,address)
target_compile_options(fuzzer PRIVATE -fsanitize=fuzzer)
target_link_libraries(fuzzer PRIVATE -fsanitize=fuzzer)
target_link_libraries(fuzzer PRIVATE diagon_lib)
target_set_common(fuzzer)
+39
View File
@@ -1,3 +1,42 @@
add_executable(input_output_test src/input_output_test.cpp)
target_link_libraries(input_output_test diagon_lib)
target_set_common(input_output_test)
option(DIAGON_ASAN "Set to ON to enable address sanitizer" OFF)
option(DIAGON_LSAN "Set to ON to enable leak sanitizer" OFF)
option(DIAGON_MSAN "Set to ON to enable memory sanitizer" OFF)
option(DIAGON_TSAN "Set to ON to enable thread sanitizer" OFF)
option(DIAGON_UBSAN "Set to ON to enable undefined behavior sanitizer" OFF)
if (NOT CMAKE_CXX_COMPILER_ID MATCHES "Clang")
return()
endif()
# Add ASAN
if (DIAGON_ASAN)
add_compile_options(-fsanitize=address)
add_link_options(-fsanitize=address)
endif()
# Add LSAN
if (DIAGON_LSAN)
add_compile_options(-fsanitize=leak)
add_link_options(-fsanitize=leak)
endif()
# Add MSAN
if (DIAGON_MSAN)
add_compile_options(-fsanitize=memory)
add_link_options(-fsanitize=memory)
endif()
# Add TSAN
if (DIAGON_TSAN)
add_compile_options(-fsanitize=thread)
add_link_options(-fsanitize=thread)
endif()
# Add UBSAN
if (DIAGON_UBSAN)
add_compile_options(-fsanitize=undefined)
add_link_options(-fsanitize=undefined)
endif()