{"id":"CVE-2023-45853","title":"MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field","summary":"MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field. NOTE: MiniZip is not a supported part of the zlib product. NOTE: pymini…","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-190"],"vendor":"zlib","product":"zlib","affected":["zlib < 1.3.1","pyminizip <= 0.2.6"],"patched":["zlib 1.3.1"],"published":"2023-10-14","updated":"2026-07-14","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2023-45853","references":[{"url":"http://www.openwall.com/lists/oss-security/2023/10/20/9","label":"cve@mitre.org"},{"url":"http://www.openwall.com/lists/oss-security/2024/01/24/10","label":"cve@mitre.org"},{"url":"https://chromium.googlesource.com/chromium/src/+/d709fb23806858847131027da95ef4c548813356","label":"cve@mitre.org"},{"url":"https://chromium.googlesource.com/chromium/src/+/de29dd6c7151d3cd37cb4cf0036800ddfb1d8b61","label":"cve@mitre.org"},{"url":"https://github.com/madler/zlib/blob/ac8f12c97d1afd9bafa9c710f827d40a407d3266/contrib/README.contrib#L1-L4","label":"cve@mitre.org"},{"url":"https://github.com/madler/zlib/pull/843","label":"cve@mitre.org"},{"url":"https://lists.debian.org/debian-lts-announce/2023/11/msg00026.html","label":"cve@mitre.org"},{"url":"https://pypi.org/project/pyminizip/#history","label":"cve@mitre.org"},{"url":"https://security.gentoo.org/glsa/202401-18","label":"cve@mitre.org"},{"url":"https://security.netapp.com/advisory/ntap-20231130-0009/","label":"cve@mitre.org"},{"url":"https://www.winimage.com/zLibDll/minizip.html","label":"cve@mitre.org"},{"url":"http://www.openwall.com/lists/oss-security/2023/10/20/9","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.openwall.com/lists/oss-security/2024/01/24/10","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://chromium.googlesource.com/chromium/src/+/d709fb23806858847131027da95ef4c548813356","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://chromium.googlesource.com/chromium/src/+/de29dd6c7151d3cd37cb4cf0036800ddfb1d8b61","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://github.com/madler/zlib/blob/ac8f12c97d1afd9bafa9c710f827d40a407d3266/contrib/README.contrib#L1-L4","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://github.com/madler/zlib/pull/843","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.debian.org/debian-lts-announce/2023/11/msg00026.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://pypi.org/project/pyminizip/#history","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.gentoo.org/glsa/202401-18","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.netapp.com/advisory/ntap-20231130-0009/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.winimage.com/zLibDll/minizip.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://cert-portal.siemens.com/productcert/html/ssa-398330.html","label":"0b142b55-0307-4c5a-b3c9-f314f3fb7c5e"},{"url":"https://cert-portal.siemens.com/productcert/html/ssa-470355.html","label":"0b142b55-0307-4c5a-b3c9-f314f3fb7c5e"},{"url":"https://cert-portal.siemens.com/productcert/html/ssa-769027.html","label":"0b142b55-0307-4c5a-b3c9-f314f3fb7c5e"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2023-45853"},{"url":"https://github.com/madler/zlib/commit/73331a6a0481067628f065ffe87bb1d8f787d10c"},{"url":"https://github.com/smihica/pyminizip"},{"url":"https://github.com/smihica/pyminizip/blob/master/zlib-1.2.11/contrib/minizip/zip.c"},{"url":"https://security.netapp.com/advisory/ntap-20231130-0009"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-45853.json"},{"url":"https://access.redhat.com/security/cve/CVE-2023-45853"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2244556"},{"url":"https://www.cve.org/CVERecord?id=CVE-2023-45853"}],"tags":["nvd","osv","pip","csaf","vex","red-hat","score-dispute"],"epss":0.03179,"epssPercentile":0.87489,"ingestedAt":"2026-07-14T13:36:54.343Z","aliases":["GHSA-mq29-j5xf-cjwr","PYSEC-2026-501"],"ecosystem":"pip","scores":{"nvd":9.8,"vendor":5.3},"slug":"CVE-2023-45853","body":"## Overview\n\nMiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field. NOTE: MiniZip is not a supported part of the zlib product. NOTE: pyminizip through 0.2.6 is also vulnerable because it bundles an affected zlib version, and exposes the applicable MiniZip code through its compress API.\n\n## Affected\n\n- `zlib < 1.3.1`\n- `pyminizip <= 0.2.6`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `zlib 1.3.1`\n\n## Package advisory (CVE-2023-45853)\n\nAffected packages:\n\n- `pyminizip <= 0.2.6`\n\nSource: https://osv.dev/vulnerability/GHSA-mq29-j5xf-cjwr\n\n## Vendor advisories\n\n- **Red Hat VEX** · Moderate · affected: Red Hat build of OpenJDK 1.8, Red Hat build of OpenJDK 11, Red Hat build of OpenJDK 17, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7 · no fix planned: Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat build of OpenJDK 1.8, Red Hat build of OpenJDK 11, … · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-45853.json)","depth":"midnight","depthScore":55,"depthScoreParts":{"impact":53.9,"likelihood":0.6,"exploitation":0,"ransomware":0},"changes":[]}