Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
8.8
CVE-2023-45853: MiniZip and pyminizip may allow attackers to crash systems with long file names
GHSA-mq29-j5xf-cjwr
CVE-2023-45853
CVE-2023-45853
Summary
MiniZip and a version of pyminizip that bundles an affected zlib library may be vulnerable to a crash if an attacker uses a very long file name, comment, or extra field. This could potentially allow an attacker to disrupt normal system operations. If you use either of these tools, it's a good idea to update to a newer version that fixes this issue.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| pip | – | pyminizip | <= 0.2.6 |
| – | zlib | zlib |
< 1.3.1 cpe:2.3:a:zlib:zlib:*:*:*:*:*:*:*:* |
| – | smihica | pyminizip |
<= 0.2.6 cpe:2.3:a:smihica:pyminizip:*:*:*:*:*:python:*:* |
Original title
MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field. NOTE: MiniZip is not a supporte...
Original description
MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field. NOTE: MiniZip is not a supported part of the zlib product. NOTE: pyminizip through 0.2.6 is also vulnerable because it bundles an affected zlib version, and exposes the applicable MiniZip code through its compress API.
ghsa CVSS3.1
9.8
Vulnerability type
CWE-190
Integer Overflow
- https://nvd.nist.gov/vuln/detail/CVE-2023-45853
- https://github.com/madler/zlib/pull/843
- https://chromium.googlesource.com/chromium/src/+/d709fb23806858847131027da95ef4c...
- https://chromium.googlesource.com/chromium/src/+/de29dd6c7151d3cd37cb4cf0036800d...
- https://github.com/madler/zlib/blob/ac8f12c97d1afd9bafa9c710f827d40a407d3266/con...
- https://www.winimage.com/zLibDll/minizip.html
- http://www.openwall.com/lists/oss-security/2023/10/20/9
- https://lists.debian.org/debian-lts-announce/2023/11/msg00026.html
- https://security.netapp.com/advisory/ntap-20231130-0009/
- https://pypi.org/project/pyminizip/#history
- https://github.com/madler/zlib/commit/73331a6a0481067628f065ffe87bb1d8f787d10c
- https://github.com/smihica/pyminizip/blob/master/zlib-1.2.11/contrib/minizip/zip...
- https://security.gentoo.org/glsa/202401-18
- http://www.openwall.com/lists/oss-security/2024/01/24/10
- https://github.com/advisories/GHSA-mq29-j5xf-cjwr
Published: 14 Oct 2023 · Updated: 15 Jul 2026 · First seen: 6 Mar 2026