Bugs

3 posts

CVEs in three strange places and the unique problem of safely processing and handling fonts.

Angus Cornall3/6/2024

Discovery and walkthrough of CVE-2023-38633 in librsvg, when two URL parser implementations (Rust and Glib) disagree on file scheme parsing leading to path traversal.

Zac Sims9/5/2023

Discovery of Headless Chromium security vulnerability, how it works, and mitigations that should be applied to similar configurations

Zac Sims4/5/2023