A crash was found while fuzz testing of the authenticode_dumper binary which can be triggered via a malformed PE file. Although this malformed file only crashes the program as-is, it could potentially be crafted further and create a security issue where these kinds of files would be able compromise the process's memory through taking advantage of affordances given by memory corruption. It's recommend to harden the code to prevent these kinds of bugs as it could greatly mitigate such this issue and even future bugs.
Hi folks,
A crash was found while fuzz testing of the authenticode_dumper binary which can be triggered via a malformed PE file. Although this malformed file only crashes the program as-is, it could potentially be crafted further and create a security issue where these kinds of files would be able compromise the process's memory through taking advantage of affordances given by memory corruption. It's recommend to harden the code to prevent these kinds of bugs as it could greatly mitigate such this issue and even future bugs.
crash.exe debug log
Repro file: https://ufile.io/6qwkgvkm