Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2023-45853: MiniZip and pyminizip may allow attackers to crash systems with long file names

CVE-2023-45853 · published 2 years ago
Summary

MiniZip and a version of pyminizip that bundles an affected zlib library may be vulnerable to a crash if an attacker uses a very long file name, comment, or extra field. This could potentially allow an attacker to disrupt normal system operations. If you use either of these tools, it's a good idea to update to a newer version that fixes this issue.

What to do
  • Update debian rootio-zlib to version 1:1.2.11.dfsg-2+deb11u2.root.io.9.
  • Update debian zlib to version 1:1.2.13.dfsg-1.aikido.5.
  • Update debian rootio-zlib to version 1:1.2.13.dfsg-1.aikido.5.
  • Update debian minizip to version 1.1-8+deb12u1.
  • Update debian zlib to version 1:1.3.dfsg-2.
  • Update zlib zlib to version 1.3.1 or later.
Affected software
Ecosystem VendorProductAffected versions
pip shin aoyama pyminizip <= 0.2.6
– zlib zlib < 1.3.1
cpe:2.3:a:zlib:zlib:*:*:*:*:*:*:*:*
– smihica pyminizip <= 0.2.6
cpe:2.3:a:smihica:pyminizip:*:*:*:*:*:python:*:*
Alpine:v3.18 alpine zlib All versions
Alpine:v3.19 alpine zlib All versions
Alpine:v3.21 alpine zlib All versions
Alpine:v3.23 alpine zlib All versions
Alpine:v3.24 alpine zlib All versions
Alpine:v3.15 alpine zlib All versions
Alpine:v3.16 alpine zlib All versions
Alpine:v3.17 alpine zlib All versions
Alpine:v3.20 alpine zlib All versions
Alpine:v3.22 alpine zlib All versions
Root:Debian:11 debian rootio-zlib < 1:1.2.11.dfsg-2+deb11u2.root.io.9
Fix: upgrade to 1:1.2.11.dfsg-2+deb11u2.root.io.9
Root:Debian:12 debian zlib < 1:1.2.13.dfsg-1.aikido.5
Fix: upgrade to 1:1.2.13.dfsg-1.aikido.5
Root:Debian:12 debian rootio-zlib < 1:1.2.13.dfsg-1.aikido.5
Fix: upgrade to 1:1.2.13.dfsg-1.aikido.5
Debian:12 debian minizip < 1.1-8+deb12u1
Fix: upgrade to 1.1-8+deb12u1
Debian:12 debian zlib All versions
Debian:13 debian zlib < 1:1.3.dfsg-2
Fix: upgrade to 1:1.3.dfsg-2
Original advisory text
MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field. NOTE: MiniZip is not a supporte...
MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field. NOTE: MiniZip is not a supported part of the zlib product. NOTE: pyminizip through 0.2.6 is also vulnerable because it bundles an affected zlib version, and exposes the applicable MiniZip code through its compress API.
Severity
9.8 Critical
CVSS 3.1: 9.8 (GHSA)
CVSS 3.1: 9.8 (OSV)
Exploitation
EPSS 3%
Type
CWE-190Integer Overflow
Timeline
Published14 Oct 2023
Updated24 Sep 2026
First seen6 Mar 2026
Track software like this
Free during beta