Zachary Ware <zachary.w...@gmail.com> added the comment: v3.9.2 is rather out of date at this point; v3.9.7 was released just yesterday and includes OpenSSL v1.1.1l. If you're concerned about issues in the version of OpenSSL included with Python v3.9.2, you are encouraged to update to the latest v3.9.7, or replace the OpenSSL DLLs with your own.
The various wininst-*.exe executables are helpers for the deprecated distutils bdist_wininst command, and you are encouraged to not use them :). You can safely remove them if you do not need bdist_wininst functionality. They will not be updated. ---------- nosy: +zach.ware resolution: -> out of date stage: -> resolved status: open -> closed title: python 3.9.2 contains wininst-10.0-amd64.exe. wininst-10.0.exe.wininst-7.1.exe. wininst-8.0.exe.wininst-9.0.exe.wininst-9.0-amd64.exe.wininst-14.0-amd64.exe and wininst-14.0.exe associates CVE-2016-9843、CVE-2016-9841、CVE-2016-9840 and CVE-2016-9842 of zlib(1.2.8, 1.2.3,1.2.5) -> python 3.9.2 contains libcrypto-1_1.dll and libssl-1_1.dll associates CVE-2021-23840\CVE-2021-3450\CVE-2021-3711\CVE-2021-3712\CVE-2021-23841\CVE-2021-3449 of openssl-1.1.1i _______________________________________ Python tracker <rep...@bugs.python.org> <https://bugs.python.org/issue45068> _______________________________________ _______________________________________________ Python-bugs-list mailing list Unsubscribe: https://mail.python.org/mailman/options/python-bugs-list/archive%40mail-archive.com