News

Google has open-sourced the Atheris code on GitHub, and the fuzzer is also available on PyPI, the Python package repository. Going forward, Google says it also plans to add support for Atheris ...
The vulnerability is in the Python tarfile package, in code that uses un-sanitized tarfile.extract() function or the built-in defaults of tarfile.extractall().