View Issue Details Jump to Notes ] Print ]
IDProjectCategoryView StatusDate SubmittedLast Update
0016060CMakeCMakepublic2016-04-12 17:522016-06-10 14:21
Reporterraysatiro 
Assigned To 
PrioritynormalSeveritymajorReproducibilityalways
StatusclosedResolutionno change required 
PlatformOSOS Version
Product Version 
Target VersionFixed in Version 
Summary0016060: Chrome warns cmake installer is harmful program
DescriptionUsing Chrome Version 49.0.2623.112 m I'm trying to download the cmake installer:

"The site ahead contains harmful programs

Attackers on cmake.org might attempt to trick you into installing programs that harm your browsing experience (for example, by changing your homepage or showing extra ads on sites you visit)."

Steps To Reproducehttps://cmake.org/download/ [^] and click on cmake-3.5.1-win32-x86.msi
Additional Informationhttps://www.google.com/transparencyreport/safebrowsing/diagnostic/index.html?hl=en-US#url=https://cmake.org/files/v3.5/cmake-3.5.1-win32-x86.msi [^]
TagsNo tags attached.
Attached Filespng file icon cmake chrome says harmful programs.PNG [^] (29,755 bytes) 2016-04-12 17:52

 Relationships

  Notes
(0040850)
Brad King (manager)
2016-04-13 08:17

Yes, we are aware that this is happening. It is almost certainly a false positive and we are trying to have it fixed.

You can verify the download by checking the SHA-256 sum of the file:

d8ab3b5dd6ba6de6c88f676dc78bbc83aa3a5ffcdc0aa7b59a8007eeceb15241 cmake-3.5.1-win32-x86.msi

You can download these to see a gpg signature of our originally uploaded files:

 https://cmake.org/files/v3.5/cmake-3.5.1-SHA-256.txt [^]
 https://cmake.org/files/v3.5/cmake-3.5.1-SHA-256.txt.asc [^]
(0040864)
Brad King (manager)
2016-04-15 08:15

This seems to be resolved now.
(0040870)
raysatiro (reporter)
2016-04-15 14:38

Thanks, I can confirm there's no warning for cmake-3.5.2-win32-x86.msi in Chrome 50.0.2661.75 m. I am curious, do you know what set off their detector, was it a problem with 3.5.1 or a false positive?
(0040871)
Brad King (manager)
2016-04-15 14:46

Re 0016060:0040870: There was nothing wrong with the 3.5.1 binary. It was a false positive. They were even triggering on some of the source .zip files!
(0041192)
Kitware Robot (administrator)
2016-06-10 14:21

This issue tracker is no longer used. Further discussion of this issue may take place in the current CMake Issues page linked in the banner at the top of this page.

 Issue History
Date Modified Username Field Change
2016-04-12 17:52 raysatiro New Issue
2016-04-12 17:52 raysatiro File Added: cmake chrome says harmful programs.PNG
2016-04-13 08:17 Brad King Note Added: 0040850
2016-04-15 08:15 Brad King Note Added: 0040864
2016-04-15 08:15 Brad King Status new => resolved
2016-04-15 08:15 Brad King Resolution open => no change required
2016-04-15 14:38 raysatiro Note Added: 0040870
2016-04-15 14:46 Brad King Note Added: 0040871
2016-06-10 14:21 Kitware Robot Note Added: 0041192
2016-06-10 14:21 Kitware Robot Status resolved => closed


Copyright © 2000 - 2018 MantisBT Team