Skip to content

Add metadata-extractor CVE-2019-14262 target - #28

Open
mjkoo wants to merge 5 commits into
masterfrom
metadata-extractor-cve-2019-14262
Open

Add metadata-extractor CVE-2019-14262 target#28
mjkoo wants to merge 5 commits into
masterfrom
metadata-extractor-cve-2019-14262

Conversation

@mjkoo

@mjkoomjkoo commented Mar 9, 2021

Copy link
Copy Markdown
Contributor

Adds a new target reproducing CVE-2019-14262 (originally found by @alpire )

Discussion in the upstream issue at drewnoakes/metadata-extractor#419

Recreated from #27 (CI doesn't work on forks)

@sciencemanxsciencemanx left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

2 small things:

  • Can you change the directory/project name to metadataextractor to match the other dirs?
  • Are the corpus and poc files different (can't tell b/c can't view binary files)?

Comment threadmetadata-extractor-cve-2019-14262/.dockerignore
Comment threadmetadata-extractor-cve-2019-14262/README.md
@mjkoo

mjkoo commented Mar 9, 2021

Copy link
Copy Markdown
ContributorAuthor

Can you change the directory/project name to metadataextractor to match the other dirs?

Sure 👍

Are the corpus and poc files different (can't tell b/c can't view binary files)?

They are, but are close.

@mjkoo
mjkoo requested a review from sciencemanxMarch 9, 2021 19:45

@sciencemanxsciencemanx left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Does beta support Java yet? seems like were failing CI

@mjkoo

mjkoo commented Mar 9, 2021

Copy link
Copy Markdown
ContributorAuthor

Beta most likely has not been updated to support this, should we wait?

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@mjkoo@sciencemanx