这是indexloc提供的服务,不要输入任何密码
Skip to content

Remediate CVE-2020-26243 by updating to nanopb 0.3.9.7 or higher #7090

@jszumski

Description

@jszumski

[REQUIRED] Step 1: Describe your environment

  • Xcode version: 12.0
  • Firebase SDK version: 7.2.0
  • Installation method: CocoaPods
  • Firebase Component: nanopb

[REQUIRED] Step 2: Describe the problem

CVE-2020-26243 "nanopb: oneof fields with PB_ENABLE_MALLOC can leak memory" was reported on Nov. 11 and fixed on Nov. 26 upstream in 0.3.9.7.

Steps to reproduce:

  • Install Firebase 7.2.0
  • Observe that Google's mirror of nanopb uses 2.30906.0 (which equates to nanopb 0.3.9.6)

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

No projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions