【问题标题】:Segmentation fault when I use afl fuzzer我使用 afl fuzzer 时出现分段错误
【发布时间】:2020-04-26 13:03:18
【问题描述】:

我在弄清楚下面的代码有什么问题时遇到了问题。我运行完整的代码,并进行了大量的输入测试,并且正在按照我的意愿处理错误。我还使用 valgrind、cppchecker 之类的东西来检查我修复的错误。然后我决定使用 afl-fuzzer 对我的代码进行高级错误检测,然后由于下面的代码行,我遇到了很多崩溃。但是,大多数崩溃是由于分段错误造成的。但我似乎看不出代码有什么问题。任何帮助将不胜感激。下面是不断给出错误的函数。我认为这与sscanf有关:

Tree* insert(char* command, Tree* tree) {
    int age;
    char* name = malloc(sizeof(char) * 20);

    if (2 != sscanf(command, "i %d %20s", &age, name)){
        fprintf(stderr, "Failed to parse insert command: not enough parameters filled\n");
       // return NULL;
    }

    if (tree == NULL){
        tree = tree_create();
    }

    tree_insert(tree, age, name);

    return tree;
}

tree_create 函数

Tree* tree_create(){
Tree *tree = malloc(sizeof(Tree));
tree->root = NULL;

return tree;
}

树插入

void tree_insert(Tree* tree, int age, char* name) {
if (tree->root == NULL) {
    Node *node = calloc(1, sizeof(Node));
    node->name = name;
    node->age = age;
    node->isRoot = true;
    node->right = NULL;
    node->left = NULL;
    tree->root = node;

} else {
    node_insert(tree->root, age, name, 1);
}
}

【问题讨论】:

  • 段错误发生在哪一行代码?调试器可以立即告诉您。此外,我们真的需要看到minimal verifiable example。否则我们不知道command带来了什么值,我们不知道tree_create是如何实现的,也不知道tree_insert是如何实现的等等。

标签: c security segmentation-fault scanf american-fuzzy-lop


【解决方案1】:

主要问题在于:

char* name = malloc(sizeof(char) * 20);

if (2 != sscanf(command, "i %d %20s", &age, name)){

您的转换规范%20s 说sscanf() 可以在name 中存储20 个字符和一个空字节,但您只为19 个字符和一个空字节分配了足够的空间。 scanf() 系列函数和大多数其他函数之间的这种“一刀两断”会导致问题,而 fuzzer 应该能够找到它们。

解决方法很简单:要么将第一个 20 更改为 21,要么将第二个 20 更改为 19。哪个更好是你的判断。我们没有足够的信息来选择哪个是更好的选择。

【讨论】:

    猜你喜欢
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    • 2017-06-06
    • 2017-08-26
    • 2018-06-18
    • 2019-05-10
    • 2018-02-15
    • 2016-01-15
    相关资源
    最近更新 更多