Hello,
I have identified reproducible memory-safety issues in unshield's InstallShield header parsing code, reachable through the public CLI and library API when processing malformed local input files.
I would prefer not to disclose the PoC files or detailed crash information publicly before maintainers have had a chance to review them.
Is there a preferred private security contact, email address, or GitHub Security Advisory route for this project?
I can provide:
minimized PoC files
ASan logs
affected commit and release information
clean-checkout reproduction steps
Best regards,
Hello,
I have identified reproducible memory-safety issues in unshield's InstallShield header parsing code, reachable through the public CLI and library API when processing malformed local input files.
I would prefer not to disclose the PoC files or detailed crash information publicly before maintainers have had a chance to review them.
Is there a preferred private security contact, email address, or GitHub Security Advisory route for this project?
I can provide:
minimized PoC files
ASan logs
affected commit and release information
clean-checkout reproduction steps
Best regards,