-
Notifications
You must be signed in to change notification settings - Fork 597
Open
Labels
area/libSkiaSharp.nativeos/Windows-ClassicIssues running on Microsoft Windows using Win32 APIs (Windows.Forms or WPF)Issues running on Microsoft Windows using Win32 APIs (Windows.Forms or WPF)os/tvOStype/bug
Description
Description
https://nvd.nist.gov/vuln/detail/CVE-2024-50602 affects libexpat < 2.6.4 . Request to update third_party/libexpat to 2.6.4+ and rebuild Skia so downstream native assets like SkiaSharp do not contain the vulnerable expat.
Code
.
Expected Behavior
No response
Actual Behavior
No response
Version of SkiaSharp
2.88.9 (Previous)
Last Known Good Version of SkiaSharp
Other (Please indicate in the description)
IDE / Editor
Visual Studio Code (Windows)
Platform / Operating System
tvOS, Windows
Platform / Operating System Version
No response
Devices
No response
Relevant Screenshots
No response
Relevant Log Output
Code of Conduct
- I agree to follow this project's Code of Conduct
Metadata
Metadata
Assignees
Labels
area/libSkiaSharp.nativeos/Windows-ClassicIssues running on Microsoft Windows using Win32 APIs (Windows.Forms or WPF)Issues running on Microsoft Windows using Win32 APIs (Windows.Forms or WPF)os/tvOStype/bug
Type
Projects
Status
New