---
id: CVE-2023-45853
title: >-
  MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based
  buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or
  extra field
summary: >-
  MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based
  buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or
  extra field. NOTE: MiniZip is not a supported part of the zlib product. NOTE:
  pymini…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-190
vendor: zlib
product: zlib
affected:
  - zlib < 1.3.1
  - pyminizip <= 0.2.6
patched:
  - zlib 1.3.1
published: '2023-10-14'
updated: '2026-07-14'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2023-45853'
references:
  - url: 'http://www.openwall.com/lists/oss-security/2023/10/20/9'
    label: cve@mitre.org
  - url: 'http://www.openwall.com/lists/oss-security/2024/01/24/10'
    label: cve@mitre.org
  - url: >-
      https://chromium.googlesource.com/chromium/src/+/d709fb23806858847131027da95ef4c548813356
    label: cve@mitre.org
  - url: >-
      https://chromium.googlesource.com/chromium/src/+/de29dd6c7151d3cd37cb4cf0036800ddfb1d8b61
    label: cve@mitre.org
  - url: >-
      https://github.com/madler/zlib/blob/ac8f12c97d1afd9bafa9c710f827d40a407d3266/contrib/README.contrib#L1-L4
    label: cve@mitre.org
  - url: 'https://github.com/madler/zlib/pull/843'
    label: cve@mitre.org
  - url: 'https://lists.debian.org/debian-lts-announce/2023/11/msg00026.html'
    label: cve@mitre.org
  - url: 'https://pypi.org/project/pyminizip/#history'
    label: cve@mitre.org
  - url: 'https://security.gentoo.org/glsa/202401-18'
    label: cve@mitre.org
  - url: 'https://security.netapp.com/advisory/ntap-20231130-0009/'
    label: cve@mitre.org
  - url: 'https://www.winimage.com/zLibDll/minizip.html'
    label: cve@mitre.org
  - url: 'http://www.openwall.com/lists/oss-security/2023/10/20/9'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2024/01/24/10'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://chromium.googlesource.com/chromium/src/+/d709fb23806858847131027da95ef4c548813356
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://chromium.googlesource.com/chromium/src/+/de29dd6c7151d3cd37cb4cf0036800ddfb1d8b61
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://github.com/madler/zlib/blob/ac8f12c97d1afd9bafa9c710f827d40a407d3266/contrib/README.contrib#L1-L4
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://github.com/madler/zlib/pull/843'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://lists.debian.org/debian-lts-announce/2023/11/msg00026.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://pypi.org/project/pyminizip/#history'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.gentoo.org/glsa/202401-18'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.netapp.com/advisory/ntap-20231130-0009/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.winimage.com/zLibDll/minizip.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://cert-portal.siemens.com/productcert/html/ssa-398330.html'
    label: 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e
  - url: 'https://cert-portal.siemens.com/productcert/html/ssa-470355.html'
    label: 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e
  - url: 'https://cert-portal.siemens.com/productcert/html/ssa-769027.html'
    label: 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2023-45853'
  - url: >-
      https://github.com/madler/zlib/commit/73331a6a0481067628f065ffe87bb1d8f787d10c
  - url: 'https://github.com/smihica/pyminizip'
  - url: >-
      https://github.com/smihica/pyminizip/blob/master/zlib-1.2.11/contrib/minizip/zip.c
  - url: 'https://security.netapp.com/advisory/ntap-20231130-0009'
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-45853.json
  - url: 'https://access.redhat.com/security/cve/CVE-2023-45853'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2244556'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2023-45853'
tags:
  - nvd
  - osv
  - pip
  - csaf
  - vex
  - red-hat
  - score-dispute
epss: 0.03179
epssPercentile: 0.87511
ingestedAt: '2026-07-14T13:36:54.343Z'
aliases:
  - GHSA-mq29-j5xf-cjwr
  - PYSEC-2026-501
ecosystem: pip
scores:
  nvd: 9.8
  vendor: 5.3
---

## Overview

MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field. NOTE: MiniZip is not a supported part of the zlib product. NOTE: pyminizip through 0.2.6 is also vulnerable because it bundles an affected zlib version, and exposes the applicable MiniZip code through its compress API.

## Affected

- `zlib < 1.3.1`
- `pyminizip <= 0.2.6`

## Remediation

Upgrade past the affected range:

- `zlib 1.3.1`

## Package advisory (CVE-2023-45853)

Affected packages:

- `pyminizip <= 0.2.6`

Source: https://osv.dev/vulnerability/GHSA-mq29-j5xf-cjwr

## Vendor advisories

- **Red Hat VEX** · Moderate · affected: Red Hat build of OpenJDK 1.8, Red Hat build of OpenJDK 11, Red Hat build of OpenJDK 17, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7 · no fix planned: Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat build of OpenJDK 1.8, Red Hat build of OpenJDK 11, … · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-45853.json)
