Skip to content

Libwmf and Google's oss-fuzz #18

@bobfriesenhahn

Description

@bobfriesenhahn

It is great to see libwmf coming back to life here, and maintained by the original developer!

Certainly libwmf has been exposed to some fuzz testing (I have seen bug reports due to it), but it does not appear to be formally a project enrolled in oss-fuzz, or even included as a subordinate library by any project participating in oss-fuzz.

The GraphicsMagick oss-fuzz build includes practically all libraries it can depend on in its oss-fuzz build, except for libwmf.

If I add libwmf into GraphicsMagick's oss-build, is there now a reasonable expectation that libwmf will not immediately crash and burn?

It would be good if libwmf can enroll itself in oss-fuzz as a project in order to test the library, and the various utilities. There is a learning curve, and it would be initially painful, but there would be considerably more confidence in the project after undergoing months of fuzz testing.

Thoughts?

Bob

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions