Jump to content
M-Brig

ZLib inside the ICS FTP Client - CVE-2016-9842 - zlib:1.2.8

Recommended Posts

Hello, just a question in reference to the latest ICS FTP component, version 9.3 and ZLib. We have an older version of the component dated November 2013 and recently had a vulnerability test performed on our software. It flagged ZLib as a high vulnerable. After doing a search through all the XML files produced at compile time we noticed that the ICS FPT Client component uses Zlib . We are trying to eliminate these vulnerabilities in our software. Does anyone know if the latest version is vulnerable to these ZLib flags.

 

Thanks for all your help.

Share this post


Link to post

ICS V8.70 and later come with Zlib 1.2.12 for old Delphi releases, but automatically users the System.Zlib for Delphi 11.1 which had the same release, and newer releases hae newer Zlibs.

 

Not planning to update the built-in version for old compilers, unless there is a serious issue.

 

Angus

Share this post


Link to post

There have been other CVEs in Zlib over the years, and we were slow to update our version, which is why ICS now uses the Delphi version, at least for those using recent Delphi versions. 

 

Angus

 

Share this post


Link to post

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×