Lemon Aquarium

Challenge Information

Project: pdfbox

Type: full

Harnesses: 6

Vulnerabilities: 8


GitHubChallenge Download

AFC Challenge Performance

Number of Unique Vulnerabilities Discovered: #

Number of Teams with Scoring PoVs: 5

Number of Teams with Scoring Patches: 3

Number of Teams with Scoring Bundles: 2


Total Points Scored for this Challenge: 83.76047069101571

What design decisions were considered for this challenge?

Unlike commons-compress, where the focus was on individual challenges, this challenge embeds a large number of vulnerabilities into one full repository scan.

Why this set of vulnerabilities?

While there is a heavy focus on the Type1 font parser, there are vulnerabilities that also focus on general structure of the PDF file.

Delta vs Full and why?

Full repository scan, with a large number of vulnerabilities to test breadth of detection across the codebase.

Challenge Harnesses

  • DomXfaParserFuzzer
  • DomXmpParserFuzzer
  • PDFExtractTextFuzzer
  • PDFStreamParserFuzzer
  • PDFWriteReadFuzzer
  • PDFOCRFuzzer

Challenge Timeouts

enabled


Challenge Vulnerabilities