Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-45853

Опубликовано: 14 окт. 2023
Источник: nvd
CVSS3: 9.8
CVSS3: 8.8
EPSS Низкий

Описание

MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field. NOTE: MiniZip is not a supported part of the zlib product. NOTE: pyminizip through 0.2.6 is also vulnerable because it bundles an affected zlib version, and exposes the applicable MiniZip code through its compress API.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:zlib:zlib:*:*:*:*:*:*:*:*
Версия до 1.3.1 (исключая)
Конфигурация 2
cpe:2.3:a:smihica:pyminizip:*:*:*:*:*:python:*:*
Версия до 0.2.6 (включая)

EPSS

Процентиль: 59%
0.00382
Низкий

9.8 Critical

CVSS3

8.8 High

CVSS3

Дефекты

CWE-190
CWE-190

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 1 года назад

MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field. NOTE: MiniZip is not a supported part of the zlib product. NOTE: pyminizip through 0.2.6 is also vulnerable because it bundles an affected zlib version, and exposes the applicable MiniZip code through its compress API.

CVSS3: 5.3
redhat
больше 1 года назад

MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field. NOTE: MiniZip is not a supported part of the zlib product. NOTE: pyminizip through 0.2.6 is also vulnerable because it bundles an affected zlib version, and exposes the applicable MiniZip code through its compress API.

CVSS3: 9.8
msrc
больше 1 года назад

Описание отсутствует

CVSS3: 9.8
debian
больше 1 года назад

MiniZip in zlib through 1.3 has an integer overflow and resultant heap ...

suse-cvrf
больше 1 года назад

Security update for zlib

EPSS

Процентиль: 59%
0.00382
Низкий

9.8 Critical

CVSS3

8.8 High

CVSS3

Дефекты

CWE-190
CWE-190