CVE-2023-45853
MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.18%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field. NOTE: MiniZip is not a supported part of the zlib product. NOTE: pyminizip through 0.2.6 is also vulnerable because it bundles an affected zlib version, and exposes the applicable MiniZip code through its compress API.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 3.18% probability · 87th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-190
- Affected
- zlib/zlib · smihica/pyminizip
- Source
- cve@mitre.org
References
- http://www.openwall.com/lists/oss-security/2023/10/20/9Mailing List
- http://www.openwall.com/lists/oss-security/2024/01/24/10Mailing List
- https://chromium.googlesource.com/chromium/src/+/d709fb23806858847131027da95ef4c548813356Mailing List, Patch
- https://chromium.googlesource.com/chromium/src/+/de29dd6c7151d3cd37cb4cf0036800ddfb1d8b61Mailing List, Patch
- https://github.com/madler/zlib/blob/ac8f12c97d1afd9bafa9c710f827d40a407d3266/contrib/README.contrib#L1-L4Product
- https://github.com/madler/zlib/pull/843Issue Tracking, Patch
- https://lists.debian.org/debian-lts-announce/2023/11/msg00026.htmlMailing List, Third Party Advisory
- https://pypi.org/project/pyminizip/#historyRelease Notes
- https://security.gentoo.org/glsa/202401-18Third Party Advisory
- https://security.netapp.com/advisory/ntap-20231130-0009/Third Party Advisory
- https://www.winimage.com/zLibDll/minizip.htmlProduct
- http://www.openwall.com/lists/oss-security/2023/10/20/9Mailing List
- http://www.openwall.com/lists/oss-security/2024/01/24/10Mailing List
- https://chromium.googlesource.com/chromium/src/+/d709fb23806858847131027da95ef4c548813356Mailing List, Patch
- https://chromium.googlesource.com/chromium/src/+/de29dd6c7151d3cd37cb4cf0036800ddfb1d8b61Mailing List, Patch
- https://github.com/madler/zlib/blob/ac8f12c97d1afd9bafa9c710f827d40a407d3266/contrib/README.contrib#L1-L4Product
- https://github.com/madler/zlib/pull/843Issue Tracking, Patch
- https://lists.debian.org/debian-lts-announce/2023/11/msg00026.htmlMailing List, Third Party Advisory
- https://pypi.org/project/pyminizip/#historyRelease Notes
- https://security.gentoo.org/glsa/202401-18Third Party Advisory
- https://security.netapp.com/advisory/ntap-20231130-0009/Third Party Advisory
- https://www.winimage.com/zLibDll/minizip.htmlProduct
- https://cert-portal.siemens.com/productcert/html/ssa-398330.html
- https://cert-portal.siemens.com/productcert/html/ssa-470355.html
- https://cert-portal.siemens.com/productcert/html/ssa-769027.html
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.