Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mq29-j5xf-cjwr

Опубликовано: 14 окт. 2023
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

pyminizip affected by zlib's integer overflow/heap based buffer overflow vulnerability due to vulnerable dependency

MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field. NOTE: MiniZip is not a supported part of the zlib product.

pyminizip uses version 1.2.11 of zlib's code.

Пакеты

Наименование

pyminizip

pip
Затронутые версииВерсия исправления

<= 0.2.6

Отсутствует

EPSS

Процентиль: 59%
0.00382
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-190

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 1 года назад

MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field. NOTE: MiniZip is not a supported part of the zlib product. NOTE: pyminizip through 0.2.6 is also vulnerable because it bundles an affected zlib version, and exposes the applicable MiniZip code through its compress API.

CVSS3: 5.3
redhat
больше 1 года назад

MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field. NOTE: MiniZip is not a supported part of the zlib product. NOTE: pyminizip through 0.2.6 is also vulnerable because it bundles an affected zlib version, and exposes the applicable MiniZip code through its compress API.

CVSS3: 9.8
nvd
больше 1 года назад

MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field. NOTE: MiniZip is not a supported part of the zlib product. NOTE: pyminizip through 0.2.6 is also vulnerable because it bundles an affected zlib version, and exposes the applicable MiniZip code through its compress API.

CVSS3: 9.8
msrc
больше 1 года назад

Описание отсутствует

CVSS3: 9.8
debian
больше 1 года назад

MiniZip in zlib through 1.3 has an integer overflow and resultant heap ...

EPSS

Процентиль: 59%
0.00382
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-190