Oh, that's more concerning.
> 2023-07-17: Asked the maintainer if they successfully downloaded the binary PoC, if they have any questions and notified about the disclosure policy. No reply received.
It doesn't sound like there's a dispute over these being bugs, but the author has forgotten or ignored this issue?
But still..
* Headline: BUFFER OVERFLOWS! WRITES! (MAYBE) ARBITRARY CODE EXECUTION!
* Details: we can make it continue 1 extra cycle of a loop to write beyond a string buffer boundary. We can't make it perform arbitrary code execution but you never know.
If the string buffer abuts something important in memory (e.g. a return address on the stack), or you can manipulate things so that it does, then even 1 byte write is bad, so I wouldn't dismiss it out of hand... but it does seem like the researchers didn't find anything useful to do with their 3-byte overflow write.
Hopefully the author picks this up and fixes it.