Quantcast
Channel: BOT24
Viewing all articles
Browse latest Browse all 8064

PDF Fuzzing Fun Continued: Status Update

$
0
0
Almost five months ago, Gynvael Coldwind and I wrote about an effort to improve the security of popular PDF parsing and rendering software; back then, we were primarily focused on the Chrome PDF Renderer and latest Adobe Reader applications. In order to achieve our results, we used several hundred CPU cores to create a unique, minimal set of PDF documents aimed at optimal code coverage. That corpus, which we now consider a fundamental part of our bug hunting success, was used as fuzzing input to numerous mutation algorithms (basic bitflipping, undisclosed PDF-specific algorithms that respect the primary rules of a document’s structure, and things in between).

read more.............http://j00ru.vexillium.org/?p=1507

Viewing all articles
Browse latest Browse all 8064

Trending Articles