Code::Blocks Forums
Developer forums (C::B DEVELOPMENT STRICTLY!) => Contributions to C::B => Topic started by: m4ko on March 26, 2020, 10:20:17 am
-
Hello,
I am a security researcher and I have Discovered a security vulnerability in the Code::Blocks IDE 17.12 (newest version). It's a high severity Remote Code Execution vulnerability.
Where do I report it?
-
The first thing you'd want to do is see if it's been fixed in the years since the 17.12 release. Newer pre-release builds are here:
http://forums.codeblocks.org/?board=20.0
-
PM me. But I doubt there is anything "serious"/fixable. After all C::B is executing compilers/linkers which generate executables, so it is insecure by nature :)
-
Remote Code Execution vulnerability
I wonder though how can you access something remotely of CodeBlocks? After all it is a desktop application without any server functionality?
-
Remote Code Execution vulnerability
I wonder though how can you access something remotely of CodeBlocks? After all it is a desktop application without any server functionality?
I can see the non-working cb_koders plugin being a possible vector.
Or, the devpack plugin. Which is almost bad enough to call non-working.
Tim S.
-
Where do I report it?
Please, report things like that to one of the devs/admins via personal message Thank you.
-
Ticket 934 if you want to look at this.