modelon-community/fmi-library

Update of two security issues

modelonrobinandersson opened this issue · 5 comments

I'm creating this issue mainly to merge the two security issues mentioned earlier below:

  1. #18
  2. #19

In order to resolve these, look into the following
Issue #18, update libexpat to version TBD.
Issue #19, update zlib to version 1.2.12.

@modelonrobinandersson Is there a plan to address CVE-2022-43680 in libexpat, (the fix is in libexpat 2.5) as part of #22?

Hi @ni-nutkalit! I was not aware of this issue. I will create a new issue and see if we can have it resolved before the end of this month, or the beginning of November.

Expat has been updated to 2.5.0 with #94