Project Zero: Notes on Windows Uniscribe Fuzzing

「It is a fascinating but dire realization that even for such a well known class of bug hunting targets as font parsing implementations, it is still possible to discover new attack vectors dating back to the previous century, having remained largely unaudited until now, and being as exposed as the interfaces we already know about.」らしい。今までとは違った思考だったようで。しっかし、CVEベースで119って多いねー。