Skip to content

Is PR with fuzz target finding unpatched bugs soon after start isn't responsible disclosure? #37

Closed
@JulianVolodia

Description

@JulianVolodia

Hi!

I was talking on google/oss-fuzz#402 but as description of this repo says, maybe this is better place for some discussion and thoughts.

I still have some n00b questions so forgive me please. I have read https://security.googleblog.com/2017/05/oss-fuzz-five-months-later-and.html and some documentation out there, but still hold my horses with sharing some weapons like fuzz targets without think.

Should I run fuzz target for some grace period to see if it not founds some easy bugs, and if so - report them first privately, to fulfill responsible disclosure?

After that, post the fuzz target to upstream of fuzzed project, inform rest about improvement or so?

Thanks for answers!

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions