Robin4
(Robin)
March 14, 2023, 8:06am
1
Hi experts,
We found that zlib in opennurbs is with low version 1.2.3, do you have any plan to update it to 1.2.13 to fix a security issue (CVE-2022-37434 )?
Although this issue was found in 1.2.12 (not in 1.2.3), but updating zlib seems also necessary for the future maintenance.
Thank you!
Robin
1 Like
I asked about this four years ago and was told, “We have no plans to change the version of zlib openNURBS uses”:
Hi @darbyjohnston ,
If static linking is required, then it might be possible to use a namespace for the zlib that ships with openNURBS and tweak the openNURBS code accordingly. This type of issue is one that dynamic linking openNURBS solves.
The other option is to use a single zlib and update source as needed to resolve issues. We have no plans to change the version of zlib openNURBS uses and no plans to change the way openNURBS is statically linked.
– Dale
Though it looks like an issue for upgrading ZLIB was created two years ago so maybe there is some progress:
https://mcneel.myjetbrains.com/youtrack/issue/RH-63503
dale
(Dale Fugier)
March 14, 2023, 4:49pm
3
Hi @darbyjohnston ,
No work has been done on this - the issue is still slated for “future”.
– Dale
Robin4
(Robin)
March 15, 2023, 2:56am
4
Thank you for your information!