Project

General

Profile

Actions

Feature #5558

closed

Update 3rd party software

Added by Kayra Akman about 7 years ago. Updated almost 7 years ago.

Status:
Closed
Priority:
Normal
Assignee:
-
Target version:
-
Start date:
02/21/2017
Due date:
% Done:

0%

Estimated time:

Description

Prebuilt 3.3.6 Windows binaries include OpenSSL 1.0.2d which was released in July 2015. Latest OpenSSL 1.0.2 release is 1.0.2k released in January 2017. (OpenSSL newslog page )

SQLite version in the master branch is 3.8.10.1 released in May 2015. Just considering the performance improvements in recent SQLite versions, it would be nice if 3.16.2 was included in Wt. (SQLite chronology page )

Prebuilt 3.3.6 Windows binaries include zlib 1.2.8 released in April 2013. Latest version is 1.2.11 released in January 2017. (zlib changelog )

I suspect libpng and Haru pdf libraries shipped on Windows are also several versions behind. IMHO, the security vulnerability fixed in libpng in December 2016 alone should justify such an update.

Considering the Wt4 efforts, 3.3.7 might be used longer than previous 3.x releases. Updated 3rd party libraries on Windows would make the release more robust.

Actions #1

Updated by Roel Standaert about 7 years ago

We've updated SQLite and the Windows builds of the latest release candidate should have more recent versions of the included libraries.

Actions #2

Updated by Kayra Akman almost 7 years ago

I think this report can be closed.

Actions #3

Updated by Wim Dumon almost 7 years ago

  • Status changed from New to Closed
Actions

Also available in: Atom PDF