Re: [FD] ODR violation in Redis Raft

2024-01-18 Thread Jeffrey Walton
On Wed, Jan 17, 2024 at 3:29 PM Meng Ruijie wrote: > > [Suggested description] > Redis raft master-1b8bd86 to master-7b46079 was discovered to contain an ODR > violation via the component hiredisAllocFns at > /opt/fs/redisraft/deps/hiredis/alloc.c. > > [VulnerabilityType Other] > AddressSanitize

[FD] Minor firefox DoS - semi silently polluting ~/Downloads with files (part 2)

2024-01-18 Thread Georgi Guninski
Minor firefox DoS - semi silently polluting ~/Downloads with files (part 2) Tested on: firefox 121 and chrome 120 on GNU/linux Date: Thu Jan 18 08:38:28 AM UTC 2024 This is barely a DoS, but since it might affect Chrome too we decided to disclose it. If firefox user visits a specially crafted p