Code::Blocks Forums

Developer forums (C::B DEVELOPMENT STRICTLY!) => Contributions to C::B => Topic started by: m4ko on March 26, 2020, 10:20:17 am

Title: Security vulnerability
Post by: m4ko on March 26, 2020, 10:20:17 am
Hello,

I am a security researcher and I have Discovered a security vulnerability in the Code::Blocks IDE 17.12 (newest version). It's a high severity Remote Code Execution vulnerability.

Where do I report it?
Title: Re: Security vulnerability
Post by: raynebc on March 26, 2020, 04:54:00 pm
The first thing you'd want to do is see if it's been fixed in the years since the 17.12 release.  Newer pre-release builds are here:
http://forums.codeblocks.org/?board=20.0
Title: Re: Security vulnerability
Post by: oBFusCATed on March 26, 2020, 08:40:26 pm
PM me. But I doubt there is anything "serious"/fixable. After all C::B is executing compilers/linkers which generate executables, so it is insecure by nature :)
Title: Re: Security vulnerability
Post by: sodev on March 26, 2020, 09:08:53 pm
Remote Code Execution vulnerability

I wonder though how can you access something remotely of CodeBlocks? After all it is a desktop application without any server functionality?
Title: Re: Security vulnerability
Post by: stahta01 on March 26, 2020, 10:03:24 pm
Remote Code Execution vulnerability

I wonder though how can you access something remotely of CodeBlocks? After all it is a desktop application without any server functionality?

I can see the non-working cb_koders plugin being a possible vector.
Or, the devpack plugin. Which is almost bad enough to call non-working.

Tim S.
Title: Re: Security vulnerability
Post by: MortenMacFly on March 29, 2020, 04:52:38 pm


Where do I report it?

Please, report things like that to one of the devs/admins via personal message Thank you.
Title: Re: Security vulnerability
Post by: oBFusCATed on March 29, 2020, 05:18:53 pm
Ticket 934 if you want to look at this.