Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2023-45853: MiniZip and pyminizip may allow attackers to crash systems with long file names
CVE-2023-45853 · published 2 years ago
Summary
MiniZip and a version of pyminizip that bundles an affected zlib library may be vulnerable to a crash if an attacker uses a very long file name, comment, or extra field. This could potentially allow an attacker to disrupt normal system operations. If you use either of these tools, it's a good idea to update to a newer version that fixes this issue.
What to do
- Update debian rootio-zlib to version 1:1.2.11.dfsg-2+deb11u2.root.io.9.
- Update debian zlib to version 1:1.2.13.dfsg-1.aikido.5.
- Update debian rootio-zlib to version 1:1.2.13.dfsg-1.aikido.5.
- Update debian minizip to version 1.1-8+deb12u1.
- Update debian zlib to version 1:1.3.dfsg-2.
- Update zlib zlib to version 1.3.1 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| pip | shin aoyama | pyminizip | <= 0.2.6 |
| – | zlib | zlib |
< 1.3.1 cpe:2.3:a:zlib:zlib:*:*:*:*:*:*:*:* |
| – | smihica | pyminizip |
<= 0.2.6 cpe:2.3:a:smihica:pyminizip:*:*:*:*:*:python:*:* |
| Alpine:v3.18 | alpine | zlib | All versions |
| Alpine:v3.19 | alpine | zlib | All versions |
| Alpine:v3.21 | alpine | zlib | All versions |
| Alpine:v3.23 | alpine | zlib | All versions |
| Alpine:v3.24 | alpine | zlib | All versions |
| Alpine:v3.15 | alpine | zlib | All versions |
| Alpine:v3.16 | alpine | zlib | All versions |
| Alpine:v3.17 | alpine | zlib | All versions |
| Alpine:v3.20 | alpine | zlib | All versions |
| Alpine:v3.22 | alpine | zlib | All versions |
| Root:Debian:11 | debian | rootio-zlib |
< 1:1.2.11.dfsg-2+deb11u2.root.io.9 Fix: upgrade to 1:1.2.11.dfsg-2+deb11u2.root.io.9
|
| Root:Debian:12 | debian | zlib |
< 1:1.2.13.dfsg-1.aikido.5 Fix: upgrade to 1:1.2.13.dfsg-1.aikido.5
|
| Root:Debian:12 | debian | rootio-zlib |
< 1:1.2.13.dfsg-1.aikido.5 Fix: upgrade to 1:1.2.13.dfsg-1.aikido.5
|
| Debian:12 | debian | minizip |
< 1.1-8+deb12u1 Fix: upgrade to 1.1-8+deb12u1
|
| Debian:12 | debian | zlib | All versions |
| Debian:13 | debian | zlib |
< 1:1.3.dfsg-2 Fix: upgrade to 1:1.3.dfsg-2
|
Original advisory text
MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field. NOTE: MiniZip is not a supporte...
MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field. NOTE: MiniZip is not a supported part of the zlib product. NOTE: pyminizip through 0.2.6 is also vulnerable because it bundles an affected zlib version, and exposes the applicable MiniZip code through its compress API.
References
- https://nvd.nist.gov/vuln/detail/CVE-2023-45853
- https://github.com/madler/zlib/pull/843
- https://chromium.googlesource.com/chromium/src/+/d709fb23806858847131027da95ef4c...
- https://chromium.googlesource.com/chromium/src/+/de29dd6c7151d3cd37cb4cf0036800d...
- https://github.com/madler/zlib/blob/ac8f12c97d1afd9bafa9c710f827d40a407d3266/con...
- https://www.winimage.com/zLibDll/minizip.html
- http://www.openwall.com/lists/oss-security/2023/10/20/9
- https://lists.debian.org/debian-lts-announce/2023/11/msg00026.html
- https://security.netapp.com/advisory/ntap-20231130-0009/
- https://pypi.org/project/pyminizip/#history
- https://github.com/madler/zlib/commit/73331a6a0481067628f065ffe87bb1d8f787d10c
- https://github.com/smihica/pyminizip/blob/master/zlib-1.2.11/contrib/minizip/zip...
- https://security.gentoo.org/glsa/202401-18
- http://www.openwall.com/lists/oss-security/2024/01/24/10
- https://github.com/advisories/GHSA-mq29-j5xf-cjwr
- https://security.alpinelinux.org/vuln/CVE-2023-45853 Vendor Advisory
- https://security-tracker.debian.org/tracker/CVE-2023-45853 Vendor Advisory
Severity
9.8
Critical
CVSS 3.1: 9.8 (GHSA)
CVSS 3.1: 9.8 (OSV)
Exploitation
EPSS 3%
Type
CWE-190Integer Overflow
Timeline
Published14 Oct 2023
Updated24 Sep 2026
First seen6 Mar 2026
Sources
ALPINE-CVE-2023-45853 · OSV
GHSA-mq29-j5xf-cjwr · GHSA
CVE-2023-45853 · NVD
CVE-2023-45853 · MITRE
DEBIAN-CVE-2023-45853 · OSV
Track software like this
Free during beta