Replies: 1 comment
-
Yes thank good point, we need to schedule an update |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Hi!
It has come to my attention that Expat is used with
XML_DTD
undefined here…https://github.com/osmandapp/OsmAnd-core/blob/e88a878300eb80c7a526ae54c245b6e22f1bf8cf/externals/expat/expat_config.h.ios#L66
… which is a security problem with all releases prior to Expat 2.6.0 that was released today. There are at least two known ways forward for OsmAnd to address this issue: (a) enabling
XML_DTD
or (b) making the build require Expat >=2.6.0. For both then to release new binaries. I know little about OsmAnd so I may be missing something. What do you think?Best, Sebastian
Beta Was this translation helpful? Give feedback.
All reactions