Current builds have 8 known security vulnerabilities

Moderator: Project members

Post Reply
Message
Author
dts350z
500 Command not understood
Posts: 3
Joined: 2016-08-09 20:27

Current builds have 8 known security vulnerabilities

#1 Post by dts350z » 2016-08-09 20:37

Hi,

Synopsys Protecode SC is reporting 8 Vulnerabilities in the current (and nightly) windows build of Filezilla.

Component Libpng 1.6.2 has 7, and expat 2.1.1 has 1.

CVE Date CVSS Type
CVE-2014-9495 2015-01-10 10 Exact match
CVE-2016-3751 2016-07-11 7.5 Exact match
CVE-2015-8472 2016-01-21 7.5 Exact match
CVE-2015-8126 2015-11-13 7.5 Exact match
CVE-2015-0973 2015-01-18 7.5 Exact match
CVE-2014-0333 2014-02-27 5 Exact match
CVE-2013-6954 2014-01-12 5 Exact match
CVE Date CVSS Type
CVE-2016-4472 2016-06-30 6.8 Exact match

Both of those components have newer versions.

Would like to re-test with the newer components.

Thanks

User avatar
botg
Site Admin
Posts: 35558
Joined: 2004-02-23 20:49
First name: Tim
Last name: Kosse

Re: Current builds have 8 known security vulnerabilities

#2 Post by botg » 2016-08-09 21:15

FileZilla uses wxWidgets which bundles these libraries. You need to report vulnerabilities in wxWidgets to the wxWidgets bug tracker: http://trac.wxwidgets.org/

These vulnerabilities do not affect FileZilla, it does not deal with PNG or XML files from untrusted sources.

dts350z
500 Command not understood
Posts: 3
Joined: 2016-08-09 20:27

Re: Current builds have 8 known security vulnerabilities

#3 Post by dts350z » 2016-08-11 15:04

Thanks,

I filed a ticket over there and it is in moderation.

dts350z
500 Command not understood
Posts: 3
Joined: 2016-08-09 20:27

Re: Current builds have 8 known security vulnerabilities

#4 Post by dts350z » 2016-08-13 14:59

WxWidgets trouble ticket system is indicating that they upgraded the version of libpng 7 months ago.

Can you not consume their latest version?

User avatar
botg
Site Admin
Posts: 35558
Joined: 2004-02-23 20:49
First name: Tim
Last name: Kosse

Re: Current builds have 8 known security vulnerabilities

#5 Post by botg » 2016-08-13 18:15

They have only updated it in unstable development versions that aren't fit for production. They did not update it in the stable branch.


As a matter of fact I'm already using the latest snapshots of the stable branch which haven't been released yet.

Post Reply