CVE-2023-45853
CVSS 9.8 - CRITICAL
Description
MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field. NOTE: MiniZip is not a supported part of the zlib product. NOTE: pyminizip through 0.2.6 is also vulnerable because it bundles an affected zlib version, and exposes the applicable MiniZip code through its compress API.
Affected Products
2| Vendor | Product | Version |
|---|---|---|
| zlib | zlib |
All versions
|
| smihica | pyminizip |
All versions
|
References
Weakness Types
CWE-190
CWE-190
CVE Information
- CVE ID:
CVE-2023-45853- Published:
- 2023-10-14
- Modified:
- 2024-12-20
- CVSS Score:
- 9.8
- Severity:
- CRITICAL
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Vendors
zlib
smihica
Quick Actions
CVSS Severity Scale
0.0 - 3.9
LOW
4.0 - 6.9
MEDIUM
7.0 - 8.9
HIGH
9.0 - 10.0
CRITICAL