Bug#774016: unar: null pointer dereference on corrupted ARJ file

2014-12-27 Thread Jakub Wilk
* Jakub Wilk , 2014-12-27, 13:02: This bug was found using American fuzzy lop: https://packages.debian.org/experimental/afl To clarify, I didn't fuzz unar itself. I did fuzz ARJ, and then tested the discovered crasher (see #774015) on unar. I'd encourage unar maintainers to perform fuzzing w

Bug#774016: unar: null pointer dereference on corrupted ARJ file

2014-12-27 Thread Jakub Wilk
Package: unar Version: 1.8.1-3+b1 Usertags: afl unar dereferences null pointer when trying to unpack the attached (slightly corrupted) ARJ file: $ unar crash.arj crash.arj: ARJ limerick (191 B)... Segmentation fault This bug was found using American fuzzy lop: https://packages.debian.org/e