Security updates are implemented in the latest release of the software.
The corrective action for a vulnerability is consequently to update the software to the latest release, or to a release reported as safe by the vulnerability's CVE report or by PeaZip's change log https://peazip.github.io/changelog.html
Backporting a fix to an older X.Y.Z version is possible by working on the sourcecode of the target version, which is available as peazip-X.Y.Z.src.zip package on https://github.com/peazip/PeaZip/releases/
Detailed instructions for compiling the application's binaries, and assembling a working package, are available at https://peazip.github.io/peazip-sources.html
Vulnerabilities should be reported to developer's email, to allow time for a thorough analisys and implementation of corrective actions before public disclosure, to minimize risks for users.
Please read https://peazip.github.io/peazip-more.html for the developer's email address, link to CVE databases containing previously disclosed vulnerabilities, and link to the Issue Tracker - which, for historical reasons, is hosted on SourceForge.
To help understanding the reported vulnerability please provide:
- Step-by-step instructions to reproduce the issue
- Version(s) tested for the issue, e.g. "Windows Portable package X.Y.Z version"
- Any special configuration required to reproduce the issue (if applicable)
- Proof-of-concept or exploit code (if possible)
- Impact of the issue, including how an attacker might exploit the issue
Thank you in advance for helping PeaZip project to grow and to keep providing a safe experience for users.
The preferred language for all communications is English.