-
Notifications
You must be signed in to change notification settings - Fork 145
Open
Labels
need-infoFurther information from issue author is requestedFurther information from issue author is requested
Description
Hi,
I’d like to bring to your attention a potential security concern I noticed related to the rm_digest_steal function.
From my understanding, this function is called by rm_tm_extract, where the buffer length is 0x200. It seems that the parameter controlling the write to this buffer might be controllable, which could pose a security risk.
However, I want to emphasize that I haven’t verified this issue myself, and my confidence level in this observation is about 50%.
Please consider reviewing this when you have time. I’m happy to provide more details or collaborate if needed.
Thank you for your hard work on this project!
fermino
Metadata
Metadata
Assignees
Labels
need-infoFurther information from issue author is requestedFurther information from issue author is requested