CVE-2023-45853
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Oct 14, 2023
Updated: Dec 20, 2024
CWE ID 190
Summary
CVE-2023-45853 is a vulnerability affecting MiniZip in certain versions of zlib up to 1.3. This issue involves an integer overflow and subsequent heap-based buffer overflow in the function zipOpenNewFileInZip4_64. The vulnerability can be triggered through a long filename, comment, or extra field. note that MiniZip is not a part of the zlib product, but the vulnerability also impacts pyminizip up to version 0.2.6 due to its bundled and exposed MiniZip code through the compress API.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- ZLIB