8295530: Update Zlib Data Compression Library to Version 1.2.13 #69
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Backporting zlib 1.2.13 from JDK17u due to https://nvd.nist.gov/vuln/detail/CVE-2022-37434 (9.8 CVSS score)
Verified on Windows which is generally the only platform I use which uses bundled zlib. This makes the
zlib
directory in the source identical to the one for JDK17u so should not cause any problems. I'll look at the feasibility of doing the same to JDK8 too.Progress
Issue
Reviewing
Using
git
Checkout this PR locally:
$ git fetch https://git.openjdk.org/jdk11u pull/69/head:pull/69
$ git checkout pull/69
Update a local copy of the PR:
$ git checkout pull/69
$ git pull https://git.openjdk.org/jdk11u pull/69/head
Using Skara CLI tools
Checkout this PR locally:
$ git pr checkout 69
View PR using the GUI difftool:
$ git pr show -t 69
Using diff file
Download this PR as a diff file:
https://git.openjdk.org/jdk11u/pull/69.diff