|
|
|
|
|
by hobls
2853 days ago
|
|
> Or in other words, a fuzzer is a program that tries to create source code that finds bugs in a compiler. This is a very narrow definition of a fuzzer. There are a lot of types of fuzzer that do not generate source code, and are not intended to test compilers. |
|
Suffice it to say, we found lots of bugs, the most famous one being what my grad advisor called the vacuum bug that could read a web client's environment variables (among other things): https://archive.nytimes.com/www.nytimes.com/library/cyber/un...