Report anything exploitable privately: use
GitHub's private advisory form, or
reach jaenster on Discord. Please do not open a public issue for a
memory-safety bug in the parsers.
Expect a first answer within a few days. This is a spare-time project and there is no bounty.
libd2 parses untrusted input by design — a save file, an MPQ archive, a packet off the wire — and is embedded in other people's programs through the C ABI, npm, crates.io and NuGet. So:
- a crafted
.d2s,.ds1,.dt1,.dc6,.mpqor packet that reads or writes out of bounds, or that panics a host program in release mode - anything reachable through the C ABI that corrupts the caller's memory rather than returning an error
- a wasm build that escapes its own linear memory
- Wrong results. A generator that disagrees with the game is a correctness bug — file it in the open, with the seed.
- Anything about running a game server. That lives in d2-dedicated-server.
- Panics from a debug build asserting on input it documents as trusted.
The tip of main and the newest vX.Y.Z release. The language bindings are on their own version
tracks; a fix may need a release on both.