CVE-2023-45853

Severity CVSS v4.0:
Pending analysis
Type:
CWE-190 Integer Overflow or Wraparound
Publication date:
14/10/2023
Last modified:
20/12/2024

Description

MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field. NOTE: MiniZip is not a supported part of the zlib product. NOTE: pyminizip through 0.2.6 is also vulnerable because it bundles an affected zlib version, and exposes the applicable MiniZip code through its compress API.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:zlib:zlib:*:*:*:*:*:*:*:* 1.3.1 (excluding)
cpe:2.3:a:smihica:pyminizip:*:*:*:*:*:python:*:* 0.2.6 (including)