Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Vulnerability in SAS7BCAT reader #729

Open
MichaelChirico opened this issue Jul 25, 2023 · 2 comments
Open

Vulnerability in SAS7BCAT reader #729

MichaelChirico opened this issue Jul 25, 2023 · 2 comments
Labels
bug an unexpected problem or unintended behavior readstat

Comments

@MichaelChirico
Copy link

Surfacing this security issue here in case (1) anyone is keen to fix it and (2) as a flag to update the bundled sources once a fix is available.

WizardMac/ReadStat#299

@MichaelChirico
Copy link
Author

FYI: there is a patch upstream:

WizardMac/ReadStat#303

Not clear how long it will take for that to be merged, so a cherry-pick may be prudent.

@gorcha gorcha added readstat bug an unexpected problem or unintended behavior labels Aug 28, 2023
@gorcha
Copy link
Member

gorcha commented Aug 28, 2023

Hi @MichaelChirico, thanks for the heads up!

Our preference is to wait for the changes to be made upstream so we don't diverge too much, but I'll keep this in mind next time we have changes to the readstat code.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug an unexpected problem or unintended behavior readstat
Projects
None yet
Development

No branches or pull requests

2 participants