← Vulnerability feed

Vulnerability record · CVE-2023-45853 · published 14 October 2023

CVE-2023-45853: Zlib integer overflow vulnerability

Zlib · Zlib

MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field. NOTE: MiniZip is not a supported part of the zlib product. NOTE: pyminizip through 0.2.6 is also vulnerable because it bundles an affected zlib version, and exposes the applicable MiniZip code through its compress API.

9.8 CVSS 3.1 Critical EPSS 3.2% · top 12.4% CWE-190 · Integer overflow
9.8CVSS 3.1 base score
3.2%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
25References
14 Jul 2026Last modified by NVD

Description

MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field. NOTE: MiniZip is not a supported part of the zlib product. NOTE: pyminizip through 0.2.6 is also vulnerable because it bundles an affected zlib version, and exposes the applicable MiniZip code through its compress API.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://www.openwall.com/lists/oss-security/2023/10/20/9 Mailing List
http://www.openwall.com/lists/oss-security/2024/01/24/10 Mailing List
https://chromium.googlesource.com/chromium/src/+/d709fb23806858847131027da95ef4c548813356 Mailing ListPatch
https://chromium.googlesource.com/chromium/src/+/de29dd6c7151d3cd37cb4cf0036800ddfb1d8b61 Mailing ListPatch
https://github.com/madler/zlib/blob/ac8f12c97d1afd9bafa9c710f827d40a407d3266/contrib/README.contrib#L1-L4 Product
https://github.com/madler/zlib/pull/843 Issue TrackingPatch
https://lists.debian.org/debian-lts-announce/2023/11/msg00026.html Mailing ListThird Party Advisory
https://pypi.org/project/pyminizip/#history Release Notes
https://security.gentoo.org/glsa/202401-18 Third Party Advisory
https://security.netapp.com/advisory/ntap-20231130-0009/ Third Party Advisory
https://www.winimage.com/zLibDll/minizip.html Product
http://www.openwall.com/lists/oss-security/2023/10/20/9 Mailing List
http://www.openwall.com/lists/oss-security/2024/01/24/10 Mailing List
https://chromium.googlesource.com/chromium/src/+/d709fb23806858847131027da95ef4c548813356 Mailing ListPatch
https://chromium.googlesource.com/chromium/src/+/de29dd6c7151d3cd37cb4cf0036800ddfb1d8b61 Mailing ListPatch
https://github.com/madler/zlib/blob/ac8f12c97d1afd9bafa9c710f827d40a407d3266/contrib/README.contrib#L1-L4 Product
https://github.com/madler/zlib/pull/843 Issue TrackingPatch
https://lists.debian.org/debian-lts-announce/2023/11/msg00026.html Mailing ListThird Party Advisory
https://pypi.org/project/pyminizip/#history Release Notes
https://security.gentoo.org/glsa/202401-18 Third Party Advisory
https://security.netapp.com/advisory/ntap-20231130-0009/ Third Party Advisory
https://www.winimage.com/zLibDll/minizip.html Product
https://cert-portal.siemens.com/productcert/html/ssa-398330.html
https://cert-portal.siemens.com/productcert/html/ssa-470355.html
https://cert-portal.siemens.com/productcert/html/ssa-769027.html

Track CVE-2023-45853 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-37434Zlib out-of-bounds write vulnerabilityzlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only appl…EPSS 18%9.8CVE-2016-9841Zlib vulnerabilityinffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.EPSS 7.6%9.8CVE-2016-9843Zlib vulnerabilityThe crc32_big function in crc32.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving big-endian C…EPSS 5.8%9.8CVE-2002-0059Zlib double free vulnerabilityThe decompression algorithm in zlib 1.1.3 and earlier, as used in many different utilities and packages, causes inflateEnd to release certain memory …EPSS 9.7%8.8CVE-2016-9840Boost vulnerabilityinftrees.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.EPSS 4.8%8.8CVE-2016-9842Zlib vulnerabilityThe inflateMark function in inflate.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving left shi…EPSS 5.2%7.5CVE-2018-25032zlib deflate out-of-bounds write on distant matcheszlib before 1.2.12 allows memory corruption when deflating (compressing) input that contains many distant matches, an out-of-bounds write (CWE-787). …EPSS 52%analysed7.5CVE-2005-2096Zlib vulnerabilityzlib 1.2 and later versions allows remote attackers to cause a denial of service (crash) via a crafted compressed stream with an incomplete code desc…EPSS 5.6%

Source: NIST National Vulnerability Database (record CVE-2023-45853), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.