update zlib to 1.2.11

These are the changes updating zlib from 1.2.8 to 1.2.10. It is only used when building without a system zlib.

The new release includes fixes for security issues CVE-2016-9840, CVE-2016-9841, CVE-2016-9842, CVE-2016-9843.

Note: Only Windows and macOS are affected by this issue. Linux packages use the system zlib.

  • Disclosure date: 2017-01-05 (Python issue bpo-29169 reported)
  • Reported at: 2017-01-02 (zlib 1.2.10 released)

Fixed In

Python issue

update zlib to 1.2.11.

  • Python issue: bpo-29169
  • Creation date: 2017-01-05
  • Reporter: Matthias Klose

Timeline

Timeline using the disclosure date 2017-01-05 as reference: