]> granicus.if.org Git - php/commitdiff
Add new entries for exif and unserialize fuzzing corpus
authorNikita Popov <nikita.ppv@gmail.com>
Tue, 24 Sep 2019 10:34:30 +0000 (12:34 +0200)
committerNikita Popov <nikita.ppv@gmail.com>
Tue, 24 Sep 2019 10:34:30 +0000 (12:34 +0200)
sapi/fuzzer/corpus/exif/duplicate_copyright_tag_leak.tiff [new file with mode: 0644]
sapi/fuzzer/corpus/exif/tag_with_illegal_zero_components.jpeg [new file with mode: 0644]
sapi/fuzzer/corpus/exif/temporary_buffer_leak.jpg [new file with mode: 0644]
sapi/fuzzer/corpus/exif/zero_length_makernote_leak.tiff [new file with mode: 0644]
sapi/fuzzer/corpus/unserialize/int_min_iv [new file with mode: 0644]
sapi/fuzzer/corpus/unserialize/leak_17628 [new file with mode: 0644]
sapi/fuzzer/corpus/unserialize/leak_17639 [new file with mode: 0644]
sapi/fuzzer/corpus/unserialize/leak_17646 [new file with mode: 0644]
sapi/fuzzer/corpus/unserialize/splobjectstorage_negative_count [new file with mode: 0644]

diff --git a/sapi/fuzzer/corpus/exif/duplicate_copyright_tag_leak.tiff b/sapi/fuzzer/corpus/exif/duplicate_copyright_tag_leak.tiff
new file mode 100644 (file)
index 0000000..48c7fe6
Binary files /dev/null and b/sapi/fuzzer/corpus/exif/duplicate_copyright_tag_leak.tiff differ
diff --git a/sapi/fuzzer/corpus/exif/tag_with_illegal_zero_components.jpeg b/sapi/fuzzer/corpus/exif/tag_with_illegal_zero_components.jpeg
new file mode 100644 (file)
index 0000000..c000b93
Binary files /dev/null and b/sapi/fuzzer/corpus/exif/tag_with_illegal_zero_components.jpeg differ
diff --git a/sapi/fuzzer/corpus/exif/temporary_buffer_leak.jpg b/sapi/fuzzer/corpus/exif/temporary_buffer_leak.jpg
new file mode 100644 (file)
index 0000000..c9f7ce8
Binary files /dev/null and b/sapi/fuzzer/corpus/exif/temporary_buffer_leak.jpg differ
diff --git a/sapi/fuzzer/corpus/exif/zero_length_makernote_leak.tiff b/sapi/fuzzer/corpus/exif/zero_length_makernote_leak.tiff
new file mode 100644 (file)
index 0000000..f1541b3
Binary files /dev/null and b/sapi/fuzzer/corpus/exif/zero_length_makernote_leak.tiff differ
diff --git a/sapi/fuzzer/corpus/unserialize/int_min_iv b/sapi/fuzzer/corpus/unserialize/int_min_iv
new file mode 100644 (file)
index 0000000..6900dce
--- /dev/null
@@ -0,0 +1 @@
+i:-9223372036854775808;
diff --git a/sapi/fuzzer/corpus/unserialize/leak_17628 b/sapi/fuzzer/corpus/unserialize/leak_17628
new file mode 100644 (file)
index 0000000..45fd864
--- /dev/null
@@ -0,0 +1 @@
+a:2:{i:0;O:19:"SplDoublyLinkedList":8:\ 1i:0;i:04;i:965556;a:6:{i:0;R:04;S:1:"a";i:2;i:961;a:8:{i:0;i:04;i:0;i:0026;i:0;a:2:{i:0;O:13:"RegexIterator":1: i:6176;a:8:{i:0;i:04;S:1:"a";i:2;i:96140012;s:1:"a";i:0;i:91755555500000016742;i:8;a:8:{i:0;i:048;i:2;d:0000800000001000000000000014000000000000000000000040400000004000000516742;i:9;a:8:{i:0;i:048;i:2;d:0000800000001000000000000000000000000000002;i:04;a:9:{i:5;R:11;s:4:"m000";O:9:"Eepictxon":85:{i:5;R:2;s:4:"m000";O:9:"Eepictxon":8:0i:-012;s:1:"a";i:0;i:96170026;i:0;i:04;S:1:"a";i:2;i:9617006;a:7:{i:6;a:7:{i:0;a:9:{i:5;R:1;s:4:"m000";O:9:"Eepictxon":86:{i:5;R:2;s:4:"m000";O:9:"Eepictxon":8:0i:-01400;a:8:{i:0;i:04;i:0;i:0026;i:0;a:2:{i:0;a:2:{i:0;O:19:"SplDoublyLinkedList":8:\ 1i:0;86:{i:5;R:2;on":8:0i:-0140012;s:1:"a";i:0;i:96170026;i:0;i:04;S:1:"a";i:2;i:9617006;a:7:{i:07006;a:7:{i:0;a:9:{i:5;R:1;s:4:"m000";O
\ No newline at end of file
diff --git a/sapi/fuzzer/corpus/unserialize/leak_17639 b/sapi/fuzzer/corpus/unserialize/leak_17639
new file mode 100644 (file)
index 0000000..fb8625a
--- /dev/null
@@ -0,0 +1 @@
+a:7:{i:6;i:0;S:1:" ";i:1;i:6;a:8:{i:0;i:4;S:1:" ";i:2;i:9;R:4;S:1:" ";a:2:{i:5;O:13:"RegexIterator":1  i:7;a:8:{i:0;a:7:{i:0;R:10;
\ No newline at end of file
diff --git a/sapi/fuzzer/corpus/unserialize/leak_17646 b/sapi/fuzzer/corpus/unserialize/leak_17646
new file mode 100644 (file)
index 0000000..ac7969e
--- /dev/null
@@ -0,0 +1 @@
+O:13:"RegexIter\tor":3:{S:1:"x";a:9:{i:04;R:1;i:5312;O:13:"RegexIterator":53;¥i:08032617006;a:7:{i:0;R:04;S:1:"a";i:2;i:5312;O:13:"RegexIterator":53;¥i:080326170;O:1:"0":2:1s:1:"1";i:0;i:0;O:13:"Liþÿÿÿterator":2:{i:0;a:6:{i:0;O:1:"0":2:1s:1:"1";i:0;i:1;r:9;}s:1:"1";i:0;i:11111101111110;O:1:"0":4:1s:1:"0";a:6:{i:0;a:2:{i:0;O:10:"ValueError":4:{i:0;O:10:"ValueError":2:{i:0;O:10:"ValueError":4:{i:Error":4:a:7:{s:2:"\11c{i:0;";a:7:{S:O:
\ No newline at end of file
diff --git a/sapi/fuzzer/corpus/unserialize/splobjectstorage_negative_count b/sapi/fuzzer/corpus/unserialize/splobjectstorage_negative_count
new file mode 100644 (file)
index 0000000..29a3ac4
--- /dev/null
@@ -0,0 +1 @@
+C:16:"SplObjectStorage":25:{x:i:-9223372036854775808;}