MantisBT - CMake | |||||
View Issue Details | |||||
ID | Project | Category | View Status | Date Submitted | Last Update |
0016095 | CMake | CMake | public | 2016-05-05 12:36 | 2016-06-10 14:21 |
Reporter | Sebastian Pipping | ||||
Assigned To | Brad King | ||||
Priority | normal | Severity | major | Reproducibility | always |
Status | closed | Resolution | fixed | ||
Platform | OS | OS Version | |||
Product Version | CMake 3.5.2 | ||||
Target Version | CMake 3.6 | Fixed in Version | CMake 3.6 | ||
Summary | 0016095: Latest CMake bundles insecure copy of Expat | ||||
Description | I found that even recent CMake bundles a copy of libexpat in folder "Utilities/cmexpat" [1] that is 12 years old (version 1.95.2 [2]) and has known security issues. Due to the auto-detection of Expat at [3], I do not worry about users of Linux or OS X too much. How about Windows? Please consider resolving the bundled copy or update to the latest release of Expat. Thank you! Best, Sebastian [1] https://github.com/Kitware/CMake/tree/1d4ab06a7045edf366c689ba5e29bbc35d08718e/Utilities/cmexpat [^] [2] https://github.com/Kitware/CMake/blob/1d4ab06a7045edf366c689ba5e29bbc35d08718e/Utilities/cmexpat/expat.h#L732 [^] [3] https://github.com/Kitware/CMake/blob/1d4ab06a7045edf366c689ba5e29bbc35d08718e/CMakeLists.txt#L417 [^] | ||||
Steps To Reproduce | |||||
Additional Information | |||||
Tags | No tags attached. | ||||
Relationships | |||||
Attached Files | |||||
Issue History | |||||
Date Modified | Username | Field | Change | ||
2016-05-05 12:36 | Sebastian Pipping | New Issue | |||
2016-05-05 14:25 | Sean McBride | Note Added: 0041031 | |||
2016-05-05 14:30 | Sebastian Pipping | Note Added: 0041032 | |||
2016-05-06 08:26 | Brad King | Note Added: 0041033 | |||
2016-05-06 08:26 | Brad King | Assigned To | => Brad King | ||
2016-05-06 08:26 | Brad King | Status | new => resolved | ||
2016-05-06 08:26 | Brad King | Resolution | open => fixed | ||
2016-05-06 08:26 | Brad King | Fixed in Version | => CMake 3.6 | ||
2016-05-06 08:26 | Brad King | Target Version | => CMake 3.6 | ||
2016-05-06 09:26 | Sebastian Pipping | Note Added: 0041034 | |||
2016-06-04 11:14 | Sebastian Pipping | Note Added: 0041135 | |||
2016-06-04 11:14 | Sebastian Pipping | Status | resolved => feedback | ||
2016-06-04 11:14 | Sebastian Pipping | Resolution | fixed => reopened | ||
2016-06-06 09:10 | Brad King | Note Added: 0041139 | |||
2016-06-06 09:10 | Brad King | Status | feedback => resolved | ||
2016-06-06 09:10 | Brad King | Resolution | reopened => fixed | ||
2016-06-10 14:21 | Kitware Robot | Note Added: 0041156 | |||
2016-06-10 14:21 | Kitware Robot | Status | resolved => closed |
Notes | |||||
|
|||||
|
|
||||
|
|||||
|
|
||||
|
|||||
|
|
||||
|
|||||
|
|
||||
|
|||||
|
|
||||
|
|||||
|
|
||||
|
|||||
|
|