First published: Thu Feb 20 2025(Updated: )
MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field. NOTE: MiniZip is not a supported part of the zlib product. NOTE: pyminizip through 0.2.6 is also vulnerable because it bundles an affected zlib version, and exposes the applicable MiniZip code through its compress API.
Affected Software | Affected Version | How to fix |
---|---|---|
F5 BIG-IP and BIG-IQ Centralized Management | >=17.1.0<=17.1.2 | |
F5 BIG-IP and BIG-IQ Centralized Management | >=16.1.0<=16.1.5 | |
F5 BIG-IP and BIG-IQ Centralized Management | >=15.1.0<=15.1.10 | |
F5 BIG-IP and BIG-IQ Centralized Management | >=8.2.0<=8.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of F5-K000149884 is high due to the heap-based buffer overflow vulnerability.
To fix F5-K000149884, you should apply the latest patches provided by F5 for the affected products.
F5-K000149884 affects specific versions of F5 BIG-IP and F5 BIG-IQ Centralized Management within the specified version ranges.
F5-K000149884 indicates an integer overflow and subsequently a heap-based buffer overflow concerning MiniZip in zlib.
No, MiniZip is not a supported part of the zlib product as noted in F5-K000149884.