Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Out-of-bounds bug affecting faiface/beep and gopxl/beep #158

Closed
enn-msi opened this issue May 7, 2024 · 2 comments
Closed

Out-of-bounds bug affecting faiface/beep and gopxl/beep #158

enn-msi opened this issue May 7, 2024 · 2 comments

Comments

@enn-msi
Copy link

enn-msi commented May 7, 2024

Hi beep maintainers,

The company I work for utilizes the gopxl/beep package in one of our products, and we discovered an out-of-bounds read bug affecting both gopxl/beep and faiface/beep.

I would like to report this issue privately and follow responsible disclosure best practices, as it can pose a security vulnerability (Denial of Service) in scenarios where the functionality affected by the bug processes untrusted data. However, there is no security.md policy file in this repository, and I've got no reply to the emails I've sent to the maintainers/contributors (i.e., the ones I could find an email).

Could one of the project maintainers reach out to me or add the security.md policy file so I could report through Github, please?

Thanks

@dusk125
Copy link
Contributor

dusk125 commented May 7, 2024

@enn-msi please join the gopxl discord and we'll get a private channel setup for the disclosure. Thanks

@enn-msi
Copy link
Author

enn-msi commented Oct 22, 2024

fixed by #166

@enn-msi enn-msi closed this as completed Oct 22, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants