pkg.soopen package index

brew / 順位 13101

zzuf を Homebrew, apt, dnf, MacPorts, Nix, pacman でインストール

zzuf のインストール経路、実行ファイル、メタデータ、AI エージェント向けセキュリティノートを確認します。

インストール

追加のインストールコマンド

macOS

Homebrew確認済み · 100%
brew install zzuf

local Homebrew formula metadata

MacPorts確認済み · 94%
sudo port install zzuf

MacPorts ports tree · security/zzuf/Portfile · ソース: api.github.com

Linux

Debian apt確認済み · 92%
sudo apt install zzuf

Debian stable package indexes · zzuf · ソース: deb.debian.org

Fedora dnf確認済み · 92%
sudo dnf install zzuf

Fedora Rawhide package metadata · zzuf · ソース: dl.fedoraproject.org

Nix確認済み · 92%
nix profile install nixpkgs#zzuf

nixpkgs package indexes · pkgs/by-name/zz/zzuf/package.nix · ソース: api.github.com

Arch Linux pacman確認済み · 92%
sudo pacman -S zzuf

Arch Linux sync databases · zzuf · ソース: geo.mirror.pkgbuild.com

概要

パッケージ概要

Transparent application input fuzzer

コマンドとエイリアス

  • zzat
  • zzuf

履歴

プロジェクトの歴史と使われ方

zzuf is Sam Hocevar's transparent application input fuzzer. It runs a target program while intercepting file and network operations, flips bits in input data deterministically, and reports crashes or other interesting behavior.

プロジェクトの歴史

zzuf grew out of the mid-2000s security and QA fuzzing culture around media parsers, image viewers, web browsers, and command-line utilities that consumed untrusted files. The Caca Labs page describes the project as a multi-purpose fuzzer whose goal is to make input fuzzing easier and more automated rather than inventing fuzzing itself.

The project had public talks and downloadable material by 2007 and 2008, including FOSDEM 2007 and Hacker Space Festival 2008 slides linked from the project page. The same page records early tarball attachments from 2008 and later snapshots, while the current development home is GitHub.

The manual-page source documents the mature command-line model: zzuf can run one program many times, vary seeds and fuzzing ratios, limit time, memory, bytes, and crashes, fuzz stdin when no command is given, and use preload or copy modes depending on platform support.

採用の歴史

zzuf's own site names several adoption signals: Goatse Security used it against third-party applications, Adobe security researchers used it to stress-test applications and libraries, and CERT's Basic Fuzzing Framework was based on zzuf. The Fuzzing Project FAQ also lists zzuf as a simple, basic fuzzing tool for random input modification.

Its broader adoption is the classic small security-tool pattern: package managers keep a reproducible CLI available even after newer coverage-guided fuzzers became dominant, because zzuf is still useful for quick black-box corruption tests and deterministic reproducers.

使われ方

Typical usage is to prefix a command with zzuf, set a seed or seed range, and choose a corruption ratio. If a run crashes, the same seed can reproduce the mutated input; simple tools such as cat or cp can then materialize the exact fuzzed file for debugging or regression tests.

The manual also supports batch testing behavior: multiple jobs, maximum crash counts, wall-clock and CPU limits, output byte limits, memory limits, include/exclude filters, protected byte ranges, and network-fuzzing filters. That made zzuf useful both as a one-off terminal tool and as a scriptable QA/security harness.

パッケージ好きにとっての重要性

zzuf matters to package nerds because it is a compact Unix-style security tool with a long tail. It exposes a single memorable command, but underneath it depends on platform loader behavior, libc/file-operation interception, signal handling, and resource limits, which are exactly the details package maintainers have to preserve across operating systems.

It also captures a pre-AFL era of fuzzing in package form: deterministic random mutation, no source instrumentation, easy shell integration, and enough knobs to turn a simple idea into a practical crash-finding workflow.

タイムライン

  • 2007: The project page links FOSDEM 2007 zzuf presentation slides.
  • 2008: The project page links Hacker Space Festival 2008 slides and records early zzuf tarball attachments.
  • 2010: The Caca Labs attachment list records later zzuf and Mac OS X snapshot tarballs.
  • 2015-01-06: The bundled manual page source is dated 2015-01-06.
  • 2015-06-09: The Caca Labs zzuf page records its last modification by Sam Hocevar.

Related projects

  • Related projects and tools include CERT Basic Fuzzing Framework, american fuzzy lop, libFuzzer, honggfuzz, radamsa, Valgrind, AddressSanitizer, media players, image viewers, web browsers, objdump, and other parser-heavy targets for black-box fuzzing.

セキュリティ状態

リスクレベル: グリーン

narrow executable package without higher-risk signals.

リスク分類器

リスク グリーン · 信頼度 低 · appliance

理由

  • narrow executable package without higher-risk signals

信号

  • metadata:no-higher-risk-signals

インストール挙動

  • Homebrew bottle メタデータは記録されていません。

推奨レビュー

エージェントに無人実行させる前に、このツールが平文の認証情報を読むか、リモート状態を書き込むか、成果物を公開するか、プラグインを起動するかを確認してください。

実行可能ファイル

インストールされる実行可能ファイル

コマンド種類公開範囲メモ
zzat実行可能ファイルインデックス済み実行可能ファイルローカル実行可能ファイルインデックスから検出されました。
zzuf実行可能ファイルインデックス済み実行可能ファイルローカル実行可能ファイルインデックスから検出されました。

鮮度

バージョンと鮮度

これらの信号は、ページ生成時期、パッケージマネージャの活動、上流リリース比較を分けて示します。バージョン遅れは、証拠 URL と比較可能なバージョンがある場合だけ警告されます。

ページ生成日2026-08-03
マネージャ版0.15
マネージャ更新日
ローカルデータ不明
上流利用不可
検出された最新未検出
  • OK鮮度警告は生成されていません。

インストールメタデータ

パッケージメタデータ

パッケージキーbrew:zzuf
バージョン0.15
パッケージマネージャHomebrew
ホームページhttp://caca.zoy.org/wiki/zzuf
リポジトリhttps://github.com/samhocevar/zzuf
Bottle未記録
サービス宣言なし

ソースデータベース一致

他のパッケージマネージャ記録

一致は外部パッケージマネージャインデックスから取得され、ローカルの Automic Vault パッケージリンクとは分けて表示されます。

Debian apt95%

zzuf 0.15-5+b1

transparent application fuzzer

https://caca.zoy.org/wiki/zzuf

sudo apt install zzuf
  • Section: devel
  • Architecture: amd64
  • Source Package: zzuf
  • 1 依存関係
  • normalized package name match
  • 一致条件: Zzuf
Debian stable package indexes · deb.debian.org · Debian stable package indexes: zzuf from https://deb.debian.org/debian/dists/stable/main/binary-amd64/Packages.xz
Nix95%

zzuf

nix profile install nixpkgs#zzuf
  • normalized package name match
  • 一致条件: Zzuf
nixpkgs package indexes · api.github.com · nixpkgs package indexes: pkgs/by-name/zz/zzuf/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1
Ubuntu apt95%

zzuf 0.15-2build3

transparent application fuzzer

https://caca.zoy.org/wiki/zzuf

sudo apt install zzuf
  • Section: universe/devel
  • Architecture: amd64
  • 1 依存関係
  • normalized package name match
  • 一致条件: Zzuf
Ubuntu 24.04 LTS package indexes · archive.ubuntu.com · Ubuntu 24.04 LTS package indexes: zzuf from https://archive.ubuntu.com/ubuntu/dists/noble/universe/binary-amd64/Packages.gz
dnf95%

zzuf 0.15-27.fc45

Transparent application input fuzzer

http://sam.zoy.org/zzuf/

sudo dnf install zzuf
  • License: WTFPL
  • Category: Unspecified
  • Architecture: x86_64
  • Source Package: zzuf
  • 3 依存関係
  • 2 提供
  • normalized package name match
  • 一致条件: Zzuf
Fedora Rawhide package metadata · dl.fedoraproject.org · Fedora Rawhide package metadata: zzuf from https://dl.fedoraproject.org/pub/fedora/linux/development/rawhide/Everything/x86_64/os/repodata/07190dc5ae9f35ae73866675fed6d95fe6e8d9fe22c9d7cdf85862cb2ed24a4c-primary.xml.zst
pacman95%

zzuf 0.15-3

Transparent application input fuzzer

https://github.com/samhocevar/zzuf

sudo pacman -S zzuf
  • License: custom:WTF
  • Architecture: x86_64
  • 1 依存関係
  • normalized package name match
  • 一致条件: Zzuf
Arch Linux sync databases · geo.mirror.pkgbuild.com · Arch Linux sync databases: zzuf from https://geo.mirror.pkgbuild.com/extra/os/x86_64/extra.db.tar.gz
MacPorts95%

zzuf

sudo port install zzuf
  • normalized package name match
  • 一致条件: Zzuf
MacPorts ports tree · api.github.com · MacPorts ports tree: security/zzuf/Portfile from https://api.github.com/repos/macports/macports-ports/git/trees/master?recursive=1

ソース経路

リポジトリデータから生成

このページは scripts/generate-pkg-sqlite.py が生成した非公開のパッケージ SQLite アーティファクトから av-web によって提供されます。

使用ソース

  • Geiger risk classifier
  • cross-ecosystem install command graph
  • curated package history
  • external package-manager database matches
  • pkg.so package database
  • pkgdb category and tag curation