Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Potentially vulnerable PDF library used #1083

Closed
SkewedZeppelin opened this issue Aug 2, 2022 · 5 comments
Closed

Potentially vulnerable PDF library used #1083

SkewedZeppelin opened this issue Aug 2, 2022 · 5 comments

Comments

@SkewedZeppelin
Copy link

I am going though apps that use old native libraries on F-Droid: https://gitlab.com/fdroid/fdroiddata/-/merge_requests/11496/

Your app uses com.itextpdf:itextg:5.5.10 from 2016-10-07, which seems to have ~5 known security issues.
https://github.com/Swati4star/Images-to-PDF/blob/8.8.1/app/build.gradle#L98

Newer versions are available: https://github.com/itext/itextpdf/releases

@Tiklyt
Copy link
Contributor

Tiklyt commented Nov 20, 2022

Hello, I fixed this issues with the #1097 PR, can you check it ? :)

@SkewedZeppelin
Copy link
Author

@Tiklyt
that gets it done!

@jondo
Copy link

jondo commented Dec 28, 2022

I guess this issue is the reason why F-Droid marks version 8.8.1 from 2021 as "undesirable".
Please create a new release.

@Moostek
Copy link

Moostek commented Apr 16, 2023

Hello, F-Droid still reporting that the app is "vulnerable". How about this issue, please? Is there anybody to fix it, please?

@Swati4star
Copy link
Owner

Fixed with #1097

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

5 participants