Anton Stiglic astiglic@okiok.com wrote:
> > "AthlonRob" <athlonrobnf@cs.com> writes:
> >
> > > Does GnuPG actually include zlib itself, or does it just require you have
> > > zlib on your system, and then utilize that?
> >
> > The source code includes a copy of zlib, but the build process uses
> > the system zlib if available.
> I happen to compile GnuPG under Windows (using Cygwin) where
> I don't have a system zlib, so it uses the one that comes with gnupg.
> The latest version of gnupg, 1.0.6, comes with zlib version 1.1.3
> (which has the vulnerability).  So I replaced the zlib library with
> zlib version 1.1.4 and recompiled my gnupg.
> --Anton

actually you may be wrong:
Cygwin have zlib - cygz.dll
and GPG compiled with Cygwin uses it (I just checked with depends.exe)

so you need newer cygz.dll.
(unless you compile GPG with --with-included-zlib switch)

