Re: Reporting Security Violations in Software Package

2025-03-12 Thread David A. Wheeler
> On Mar 12, 2025, at 11:57 AM, Paul Smith wrote: > > On Wed, 2025-03-12 at 15:05 +, Yao Shuangjie wrote: >> We are cybersecurity researchers from the Hong Kong University of >> Science and Technology. We found several security violations of >> undefined behaviors in GNU make 4.4.1 using o

Reporting Security Violations in Software Package

2025-03-12 Thread Yao Shuangjie
Dear maintainers, We are cybersecurity researchers from the Hong Kong University of Science and Technology. We found several security violations of undefined behaviors in GNU make 4.4.1 using our novel symbolic execution technique several months ago. The details are shown below. ../src/hash.c:3

Re: Reporting Security Violations in Software Package

2025-03-12 Thread Paul Smith
On Wed, 2025-03-12 at 15:05 +, Yao Shuangjie wrote: > We are cybersecurity researchers from the Hong Kong University of > Science and Technology. We found several security violations of > undefined behaviors in GNU make 4.4.1 using our novel symbolic > execution technique several months ago. Th