From 420d0d50bcdc47c793157c2f1e143136eafa6500 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?R=C3=A9mi=20Verschelde?= Date: Thu, 31 Mar 2022 14:14:05 +0200 Subject: zlib/minizip: Update to version 1.2.12 Security update, fixes CVE-2018-25032 in zlib. Preliminary assessment doesn't show Godot as affected since we don't seem to call `deflate` with the problematic parameters, but the extent of the vulnerability is not fully clear upstream yet. --- thirdparty/zlib/inflate.h | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) (limited to 'thirdparty/zlib/inflate.h') diff --git a/thirdparty/zlib/inflate.h b/thirdparty/zlib/inflate.h index a46cce6b6d..f127b6b1fa 100644 --- a/thirdparty/zlib/inflate.h +++ b/thirdparty/zlib/inflate.h @@ -1,5 +1,5 @@ /* inflate.h -- internal inflate state definition - * Copyright (C) 1995-2016 Mark Adler + * Copyright (C) 1995-2019 Mark Adler * For conditions of distribution and use, see copyright notice in zlib.h */ @@ -86,7 +86,8 @@ struct inflate_state { int wrap; /* bit 0 true for zlib, bit 1 true for gzip, bit 2 true to validate check value */ int havedict; /* true if dictionary provided */ - int flags; /* gzip header method and flags (0 if zlib) */ + int flags; /* gzip header method and flags, 0 if zlib, or + -1 if raw or no header yet */ unsigned dmax; /* zlib header max distance (INFLATE_STRICT) */ unsigned long check; /* protected copy of check value */ unsigned long total; /* protected copy of output count */ -- cgit v1.2.3