oss-fuzz icon indicating copy to clipboard operation
oss-fuzz copied to clipboard

Report matio issues to primary contact of hdf5 group

Open tbeu opened this issue 10 months ago • 5 comments

This is due to https://github.com/HDFGroup/hdf5/issues/272 and the recently disclosed issues https://github.com/HDFGroup/hdf5/issues/4350 and https://github.com/HDFGroup/hdf5/issues/4351. Many of the found issues actually address libhdf5. I know that libhdf5 has its own oss-fuzz setup, but I cannot be sure if the reported issues for libmatio are also found there.

@derobins Being primary contact for hdf5 fuzzing report, do you approve?

tbeu avatar Apr 14 '24 07:04 tbeu

tbeu has previously contributed to projects/matio. The previous PR was #6018

github-actions[bot] avatar Apr 14 '24 07:04 github-actions[bot]

Thanks @tbeu. I will convert this to a draft for now until @derobins approves.

DonggeLiu avatar Apr 18 '24 01:04 DonggeLiu

@DonggeLiu Feel free to close if there is no response/approval by @derobins.

tbeu avatar Apr 30 '24 16:04 tbeu

You can report them to us, but I'm not going to make any promises about debugging issues through 3rd-party software until we've managed to close all of our own oss-fuzz issues. Hopefully, most of your issues will get closed as we work on our oss-fuzz issues over the summer.

derobins avatar Apr 30 '24 23:04 derobins

You can report them to us, but I'm not going to make any promises about debugging issues through 3rd-party software until we've managed to close all of our own oss-fuzz issues.

Hi @derobins, we appreciate the effort to maintain the project, and do not require immediate fixes.

Just to clarify: OSS-Fuzz has a 90-day disclosure policy. Would that be acceptable for your situation? Thanks : )

DonggeLiu avatar May 01 '24 01:05 DonggeLiu

OK, seems not desired or necessary after all.

tbeu avatar Aug 22 '24 15:08 tbeu