Open Source Development

Power Open Source Development

Explore the open source tools and capabilities for building and deploying modern applications on IBM Power platforms including AIX, IBM i, and Linux.


#Power


#Power

 View Only
  • 1.  New version of zlib

    Posted Tue August 05, 2025 08:00 AM

    Hello

    My security team is complaining about zlib 1.12.3. As version 1.13.1 is available, they are telling me that 1.12.3 is obsolete.

    So I'd like to know if you could make 1.13.1 available in aix toolbox ?

    Best regards.

    Tof



    ------------------------------
    Christophe Gehin
    ------------------------------

    #AIXOpenSource


  • 2.  RE: New version of zlib

    Posted Tue August 05, 2025 09:39 AM

    Hi,
    Let's us know the CVE reported by your security team about current zlib , so we will analyse and update.


    Thanks
    Ranjit



    ------------------------------
    Ranjit Ranjan
    ------------------------------



  • 3.  RE: New version of zlib

    Posted Tue August 05, 2025 09:49 AM

    CVE-2023-45853 

    Regards



    ------------------------------
    Christophe Gehin
    ------------------------------



  • 4.  RE: New version of zlib

    Posted Wed August 06, 2025 05:11 AM

    Hi 

    I went through the CVE-2023-45853 details and source code where fix is applied.
    This CVE is for minizip tool which we are not compiling and shipping as part of Zlib package , so Zlib update is not urgent if only this CVE is concerned.
    You can inform these details to your security team.

    Thanks
    Ranjit



    ------------------------------
    Ranjit Ranjan
    ------------------------------



  • 5.  RE: New version of zlib

    Posted 7 days ago

    Hi Ranjit

    My security team is still asking me to get and install a new version of zlid. For them, the available version is obsolete. 

    Is it planned by any chance to update zlid to a newer release ?

    Best regards



    ------------------------------
    Christophe Gehin
    ------------------------------



  • 6.  RE: New version of zlib

    Posted 6 days ago

    Yes, there is a plan to update zlib in next couple of months. 
    As mentioned earlier in the thread , the above CVE is not affecting the existing zlib in AIX Toolbox as we are not shipping minizip tool. 



    ------------------------------
    Ayappan P
    ------------------------------