Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[zlib] update to 1.3.1 #36394

Closed
carsten-grimm-at-ipolog opened this issue Jan 26, 2024 · 4 comments · Fixed by #36395
Closed

[zlib] update to 1.3.1 #36394

carsten-grimm-at-ipolog opened this issue Jan 26, 2024 · 4 comments · Fixed by #36395
Assignees
Labels
category:port-update The issue is with a library, which is requesting update new revision

Comments

@carsten-grimm-at-ipolog
Copy link
Contributor

Library name

zlib

New version number

1.3.1

Other information that may be useful (release notes, etc...)

Release notes: https://github.com/madler/zlib/releases/tag/v1.3.1

This release was also anticipated, due to an issue related to scoring vulnerabilities: madler/zlib#868

A pull request will be ready shortly.

@carsten-grimm-at-ipolog carsten-grimm-at-ipolog added the category:port-update The issue is with a library, which is requesting update new revision label Jan 26, 2024
@Neustradamus
Copy link

@carsten-grimm-at-ipolog: Thanks for your PR, 2 CVE fixes have been added into Zlib 1.3.1 for Minizip.

@dg0yt
Copy link
Contributor

dg0yt commented Jan 31, 2024

... and minizip is a separate port.

@carsten-grimm-at-ipolog
Copy link
Contributor Author

carsten-grimm-at-ipolog commented Feb 1, 2024

@carsten-grimm-at-ipolog: Thanks for your PR, 2 CVE fixes have been added into Zlib 1.3.1 for Minizip.

Thanks, @Neustradamus , for pointing this out. My understanding is that this port does not build the examples from zlib and, thus, does not build minizip. This was the case for the previous version of the port and is now simplified by the new compile option to disable the examples in zlib. Hence, even the previous version of the port for zlib 1.3 should not have been affected by CVE-2023-45853. But that may not have been obvious, especially not to vulnerability scanners that are based on version numbers.

@dg0yt, I am slightly confused. I see two ports that seem to refer to minizip: minizip and minizip-ng.

  • minizip is based on version 1.3 of madler/zlib. I do not see a patch for CVE-2023-45853 (in that port).
  • minizip-ng is based on zlib-ng/minizip-ng at version 4.0.4

I might be able to look into this on the weekend, but I cannot promise anything, as I am not familiar with minizip.

@Neustradamus
Copy link

Ok no problem, for second fixed CVE, it is CVE-2014-9485 from 2014 and the PR is here:

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
category:port-update The issue is with a library, which is requesting update new revision
Projects
None yet
Development

Successfully merging a pull request may close this issue.

4 participants