-
Notifications
You must be signed in to change notification settings - Fork 6.7k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[zlib] update to 1.3.1 #36394
Comments
@carsten-grimm-at-ipolog: Thanks for your PR, 2 CVE fixes have been added into Zlib 1.3.1 for Minizip. |
... and minizip is a separate port. |
Thanks, @Neustradamus , for pointing this out. My understanding is that this port does not build the examples from zlib and, thus, does not build minizip. This was the case for the previous version of the port and is now simplified by the new compile option to disable the examples in zlib. Hence, even the previous version of the port for zlib 1.3 should not have been affected by CVE-2023-45853. But that may not have been obvious, especially not to vulnerability scanners that are based on version numbers. @dg0yt, I am slightly confused. I see two ports that seem to refer to minizip:
I might be able to look into this on the weekend, but I cannot promise anything, as I am not familiar with minizip. |
Ok no problem, for second fixed CVE, it is CVE-2014-9485 from 2014 and the PR is here: |
Library name
zlib
New version number
1.3.1
Other information that may be useful (release notes, etc...)
Release notes: https://github.com/madler/zlib/releases/tag/v1.3.1
This release was also anticipated, due to an issue related to scoring vulnerabilities: madler/zlib#868
A pull request will be ready shortly.
The text was updated successfully, but these errors were encountered: