smihica / pyminizip

To create a password encrypted zip file in python.
Other
106 stars 37 forks source link

Update to zlib 1.3 + CVE fix in more... #52

Open Neustradamus opened 8 months ago

Neustradamus commented 8 months ago

Dear @smihica,

Can you update the code?

There is a zlib 1.3 and a CVE fix in more (you can use current git devel branch):

Note that there are other CVE fixes in previous builds too.

Example:

Thanks in advance.

JudahSchwartz commented 7 months ago

@smihica any update here?

Neustradamus commented 7 months ago

Zlib 1.3.1 has been released (2024-01-22) with 2 CVE fixes for Minizip:

asaf400 commented 3 months ago

From what I've seen, Debian 12 still hasn't created a new deb release with the fixes just for anyone who's looking for a fix with bookworm at this time: https://security-tracker.debian.org/tracker/CVE-2023-45853