orion-viewer icon indicating copy to clipboard operation
orion-viewer copied to clipboard

Potentially vulnerable PDF library used

Open SkewedZeppelin opened this issue 2 years ago • 1 comments

I am going though apps that use old native libraries on F-Droid: https://gitlab.com/fdroid/fdroiddata/-/merge_requests/11496/

Your app uses MuPDF 1.16.1 from 2019-08-02, which seems to have ~5 known security issues. https://github.com/max-kammerer/orion-viewer/commits/0.81.2_fdroid/nativeLibs/mupdfModule

Newer versions are available: https://mupdf.com/releases/history.html

SkewedZeppelin avatar Aug 02 '22 08:08 SkewedZeppelin

@SkewedZeppelin Thank you for the report!

max-kammerer avatar Aug 11 '22 08:08 max-kammerer

@SkewedZeppelin Thank you for the report! Orion 0.82.1 is shipped with mupdf 1.23.3

max-kammerer avatar Oct 07 '23 08:10 max-kammerer