summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorZachary Ware <zach@python.org>2022-11-01 18:02:51 (GMT)
committerGitHub <noreply@github.com>2022-11-01 18:02:51 (GMT)
commitc0859743d9ad3bbd4c021200f4162cfeadc0c17a (patch)
treec789e67e27a928f27925a29c0eccadf257977c1a
parentf042646595d1cdd2ecdc15222b1766f746d010f0 (diff)
downloadcpython-c0859743d9ad3bbd4c021200f4162cfeadc0c17a.zip
cpython-c0859743d9ad3bbd4c021200f4162cfeadc0c17a.tar.gz
cpython-c0859743d9ad3bbd4c021200f4162cfeadc0c17a.tar.bz2
gh-98689: Update Windows builds to zlib v1.2.13 (GH-98968)
-rw-r--r--Misc/NEWS.d/next/Windows/2022-11-01-11-07-33.gh-issue-98689.0f6e_N.rst2
-rw-r--r--PCbuild/get_externals.bat2
-rw-r--r--PCbuild/python.props2
3 files changed, 4 insertions, 2 deletions
diff --git a/Misc/NEWS.d/next/Windows/2022-11-01-11-07-33.gh-issue-98689.0f6e_N.rst b/Misc/NEWS.d/next/Windows/2022-11-01-11-07-33.gh-issue-98689.0f6e_N.rst
new file mode 100644
index 0000000..295debb
--- /dev/null
+++ b/Misc/NEWS.d/next/Windows/2022-11-01-11-07-33.gh-issue-98689.0f6e_N.rst
@@ -0,0 +1,2 @@
+Update Windows builds to zlib v1.2.13. v1.2.12 has CVE-2022-37434, but
+the vulnerable ``inflateGetHeader`` API is not used by Python.
diff --git a/PCbuild/get_externals.bat b/PCbuild/get_externals.bat
index 681c79f..98cca97 100644
--- a/PCbuild/get_externals.bat
+++ b/PCbuild/get_externals.bat
@@ -59,7 +59,7 @@ if NOT "%IncludeTkinterSrc%"=="false" set libraries=%libraries% tcl-core-8.6.12.
if NOT "%IncludeTkinterSrc%"=="false" set libraries=%libraries% tk-8.6.12.1
if NOT "%IncludeTkinterSrc%"=="false" set libraries=%libraries% tix-8.4.3.6
set libraries=%libraries% xz-5.2.5
-set libraries=%libraries% zlib-1.2.12
+set libraries=%libraries% zlib-1.2.13
for %%e in (%libraries%) do (
if exist "%EXTERNALS_DIR%\%%e" (
diff --git a/PCbuild/python.props b/PCbuild/python.props
index 5fa32df..320d41f 100644
--- a/PCbuild/python.props
+++ b/PCbuild/python.props
@@ -71,7 +71,7 @@
<opensslOutDir>$(ExternalsDir)openssl-bin-1.1.1q\$(ArchName)\</opensslOutDir>
<opensslIncludeDir>$(opensslOutDir)include</opensslIncludeDir>
<nasmDir>$(ExternalsDir)\nasm-2.11.06\</nasmDir>
- <zlibDir>$(ExternalsDir)\zlib-1.2.12\</zlibDir>
+ <zlibDir>$(ExternalsDir)\zlib-1.2.13\</zlibDir>
<!-- Suffix for all binaries when building for debug -->
<PyDebugExt Condition="'$(PyDebugExt)' == '' and $(Configuration) == 'Debug'">_d</PyDebugExt>