Description
MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field. NOTE: MiniZip is not a supported part of the zlib product. NOTE: pyminizip through 0.2.6 is also vulnerable because it bundles an affected zlib version, and exposes the applicable MiniZip code through its compress API.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3670-1 | minizip security update |
Github GHSA |
GHSA-mq29-j5xf-cjwr | pyminizip affected by zlib's integer overflow/heap based buffer overflow vulnerability due to vulnerable dependency |
Ubuntu USN |
USN-7107-1 | zlib vulnerability |
References
History
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Fri, 20 Dec 2024 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Smihica
Smihica pyminizip |
|
| CPEs | cpe:2.3:a:smihica:pyminizip:*:*:*:*:*:python:*:* | |
| Vendors & Products |
Smihica
Smihica pyminizip |
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-02T20:29:32.500Z
Reserved: 2023-10-14T00:00:00.000Z
Link: CVE-2023-45853
Updated: 2024-08-02T20:29:32.500Z
Status : Analyzed
Published: 2023-10-14T02:15:09.323
Modified: 2024-12-20T17:41:31.237
Link: CVE-2023-45853
OpenCVE Enrichment
No data.
Debian DLA
Github GHSA
Ubuntu USN