Zachary Ware <zachary.w...@gmail.com> added the comment:

v3.9.2 is rather out of date at this point; v3.9.7 was released just yesterday 
and includes OpenSSL v1.1.1l.  If you're concerned about issues in the version 
of OpenSSL included with Python v3.9.2, you are encouraged to update to the 
latest v3.9.7, or replace the OpenSSL DLLs with your own.

The various wininst-*.exe executables are helpers for the deprecated distutils 
bdist_wininst command, and you are encouraged to not use them :).  You can 
safely remove them if you do not need bdist_wininst functionality.  They will 
not be updated.

----------
nosy: +zach.ware
resolution:  -> out of date
stage:  -> resolved
status: open -> closed
title: python 3.9.2 contains wininst-10.0-amd64.exe. 
wininst-10.0.exe.wininst-7.1.exe. 
wininst-8.0.exe.wininst-9.0.exe.wininst-9.0-amd64.exe.wininst-14.0-amd64.exe 
and wininst-14.0.exe associates CVE-2016-9843、CVE-2016-9841、CVE-2016-9840 and 
CVE-2016-9842 of zlib(1.2.8, 1.2.3,1.2.5) -> python 3.9.2 contains 
libcrypto-1_1.dll and libssl-1_1.dll associates 
CVE-2021-23840\CVE-2021-3450\CVE-2021-3711\CVE-2021-3712\CVE-2021-23841\CVE-2021-3449
 of openssl-1.1.1i

_______________________________________
Python tracker <rep...@bugs.python.org>
<https://bugs.python.org/issue45068>
_______________________________________
_______________________________________________
Python-bugs-list mailing list
Unsubscribe: 
https://mail.python.org/mailman/options/python-bugs-list/archive%40mail-archive.com

Reply via email to