--- /dev/null
+Update Windows builds to zlib v1.2.13. v1.2.12 has CVE-2022-37434, but
+the vulnerable ``inflateGetHeader`` API is not used by Python.
if NOT "%IncludeTkinterSrc%"=="false" set libraries=%libraries% tk-8.6.12.1
if NOT "%IncludeTkinterSrc%"=="false" set libraries=%libraries% tix-8.4.3.6
set libraries=%libraries% xz-5.2.5
-set libraries=%libraries% zlib-1.2.12
+set libraries=%libraries% zlib-1.2.13
for %%e in (%libraries%) do (
if exist "%EXTERNALS_DIR%\%%e" (
<opensslOutDir>$(ExternalsDir)openssl-bin-1.1.1q\$(ArchName)\</opensslOutDir>
<opensslIncludeDir>$(opensslOutDir)include</opensslIncludeDir>
<nasmDir>$(ExternalsDir)\nasm-2.11.06\</nasmDir>
- <zlibDir>$(ExternalsDir)\zlib-1.2.12\</zlibDir>
+ <zlibDir>$(ExternalsDir)\zlib-1.2.13\</zlibDir>
<!-- Suffix for all binaries when building for debug -->
<PyDebugExt Condition="'$(PyDebugExt)' == '' and $(Configuration) == 'Debug'">_d</PyDebugExt>