oschwartz10612 / poppler-windows

Download Poppler binaries packaged for Windows with dependencies
MIT License
549 stars 59 forks source link

Trojan is reported for release 24.07.0-0 #70

Closed galenus closed 1 week ago

galenus commented 2 months ago

File pdffonts.exe in latest release as of today (24.07.0-0) is reported as containing malicious code by multiple antiviruses on VirusTotal.

vmario89 commented 2 months ago

this is a question of trust on the project :-/

oschwartz10612 commented 1 week ago

Hi,

Thank you for raising awareness of this issue.

In poking around online I believe this to be a false positive and/or a unreliable AV actor. Virustotal is a legitimate website that does real good, but they just feed files into many different AV vendors. It is possible to get false positives or bad results from some of the vendors. Take a look at a few of the following similar threads I have found:

I dont want to downplay this but I have taking a look around the code and PRs here and everything appears to be in good order. If this was introduced it would have been on the poppler-feedstock side. Please feel free if you are not convicned to open an issue there for more discussion.

Sorry for the delay in my response to this!

Best, Owen