CVE-2023-45853

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Oct 14, 2023
Updated: Dec 20, 2024
CWE ID 190

Summary

CVE-2023-45853 is a vulnerability affecting MiniZip in certain versions of zlib up to 1.3. This issue involves an integer overflow and subsequent heap-based buffer overflow in the function zipOpenNewFileInZip4_64. The vulnerability can be triggered through a long filename, comment, or extra field. note that MiniZip is not a part of the zlib product, but the vulnerability also impacts pyminizip up to version 0.2.6 due to its bundled and exposed MiniZip code through the compress API.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share