I have been fuzzing an open-source application which depends on VTK (9.5) as part of a security code audit and have identified a series of memory errors for a specific filetype parser in VTK.
Which would be the most appropriate channel to communicate the findings without directly releasing them?
I’ve fuzzed some VTK file readers too. Alas, there are lots of issues with the ones I tried. It has not made it to the top of my todo list, nor anyone else’s I suspect.