Skip to content

Commit 1dc25f2

Browse files
committed
Fixed an XML external entity (XXE) vulnerability.
1 parent 9ef1de7 commit 1dc25f2

File tree

4 files changed

+6
-7
lines changed

4 files changed

+6
-7
lines changed

AutoUpdater.NET/AutoUpdater.cs

Lines changed: 1 addition & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -462,8 +462,7 @@ private static void BackgroundWorkerDoWork(object sender, DoWorkEventArgs e)
462462
}
463463
else
464464
{
465-
XmlDocument receivedAppCastDocument = new XmlDocument();
466-
465+
XmlDocument receivedAppCastDocument = new XmlDocument {XmlResolver = null};
467466
try
468467
{
469468
receivedAppCastDocument.Load(appCastStream);

AutoUpdater.NET/Properties/AssemblyInfo.cs

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -32,6 +32,6 @@
3232
// You can specify all the values or you can default the Build and Revision Numbers
3333
// by using the '*' as shown below:
3434
// [assembly: AssemblyVersion("1.0.*")]
35-
[assembly: AssemblyVersion("1.5.7.0")]
36-
[assembly: AssemblyFileVersion("1.5.7.0")]
35+
[assembly: AssemblyVersion("1.5.8.0")]
36+
[assembly: AssemblyFileVersion("1.5.8.0")]
3737
[assembly: NeutralResourcesLanguageAttribute("en")]

AutoUpdater.NET/build/Autoupdater.NET.Official.nuspec

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@
22
<package xmlns="http://schemas.microsoft.com/packaging/2011/08/nuspec.xsd">
33
<metadata>
44
<id>Autoupdater.NET.Official</id>
5-
<version>1.5.7</version>
5+
<version>1.5.8</version>
66
<title>AutoUpdater.NET</title>
77
<authors>RBSoft</authors>
88
<owners>RBSoft</owners>

appveyor.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
1-
version: 1.5.7.{build}
1+
version: 1.5.8.{build}
22
environment:
3-
my_version: 1.5.7
3+
my_version: 1.5.8
44
my_secret:
55
secure: vbPRaZLQYpGPr4BrZZ4p6TofpSZMud+FKtlpqjgO8aA=
66
skip_branch_with_pr: true

0 commit comments

Comments
 (0)