zlib 1.2.12 --> 1.2.13 upgrade #7163
Replies: 2 comments 4 replies
-
We had a similar discussion on #6804 when another CVE came out. Vulnerabilities which lead to out of bounds read or write operations aren't applicable to PyInstaller's onefile extraction (the only place our statically compiled zlib is used) since to be exploited, a user would have to run an untrusted onefile executable given to them by the attacker, in which case the attacker is already able to put the malicious code into the executable rather than carefully crafting an invalid archive to do the same thing. |
Beta Was this translation helpful? Give feedback.
-
Thank you for explanation and integrating zlib update. Is there a plan for PyInstaller release with this update? |
Beta Was this translation helpful? Give feedback.
-
Hi,
there is a critical CVE https://nvd.nist.gov/vuln/detail/CVE-2022-37434 in zlib 1.2.12 which was fixed in zlib 1.2.13. Is there a plan to update this 3rd party to remove this vulnerability and to release a new version of PyInstaller?
Regards,
Michal Mirkowski
Beta Was this translation helpful? Give feedback.
All reactions