CVE-2023-45853: overflows in MiniZip in zlib through 1.3
Last updated 13 November 2024
Other sources
MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip464 via a long filename comment or extra field. NOTE: MiniZip is not a supported part of the zlib product. NOTE: pyminizip through 0.2.6 is also vulnerable because it bundles an affected zlib version and exposes the applicable MiniZip code through its compress API.
— Microsoft
MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip464 via a long filename, comment, or extra field. NOTE: MiniZip is not a supported part of the zlib product.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/minizipto a version that resolves this vulnerability.Fixed in 1.1-8+deb11u1Fixed in 1.1-8+deb12u1 - Upgrade
Upgrade
debian/zlibto a version that resolves this vulnerability.Fixed in 1:1.3.dfsg+really1.3.1-1 - Upgrade
Upgrade
zlib/MiniZipto a version that resolves this vulnerability.Fixed in 1.3 - Upgrade
Upgrade
pyminizipto a version that resolves this vulnerability.Fixed in 0.2.6
Event History
Frequently Asked Questions
What is the severity of CVE-2023-45853?
The severity of CVE-2023-45853 is critical with a CVSS score of 9.8.
What is the vulnerability description of CVE-2023-45853?
CVE-2023-45853 is a heap-based buffer overflow vulnerability in MiniZip in zlib through 1.3, which can be triggered by a long filename, comment, or extra field.
What software is affected by CVE-2023-45853?
Zlib through version 1.3 is affected by CVE-2023-45853.
Is MiniZip a supported part of the zlib product?
No, MiniZip is not a supported part of the zlib product.
How can I fix CVE-2023-45853?
To fix CVE-2023-45853, update zlib to a version that includes the patch for the vulnerability.