Hello,
I have identified a reproducible memory-safety issue in stutter's lexer/parser when processing a crafted input through the public parser entrypoint.
I would prefer not to disclose the minimized inputs or sanitizer details publicly before the maintainer has had a chance to review them.
Is there an appropriate private contact for reporting security issues in this project?
I can provide:
- affected commit information
- minimized reproducer inputs
- standalone reproduction code
- AddressSanitizer logs
- source-level root cause notes
- suggested fix direction
Best regards,
Yukimura
Hello,
I have identified a reproducible memory-safety issue in stutter's lexer/parser when processing a crafted input through the public parser entrypoint.
I would prefer not to disclose the minimized inputs or sanitizer details publicly before the maintainer has had a chance to review them.
Is there an appropriate private contact for reporting security issues in this project?
I can provide:
Best regards,
Yukimura