CVE-2023-45853Integer Overflow or Wraparound in Zlib

Severity
9.8CRITICALNVD
EPSS
1.3%
top 20.35%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 14
Latest updateOct 23

Description

MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field. NOTE: MiniZip is not a supported part of the zlib product. NOTE: pyminizip through 0.2.6 is also vulnerable because it bundles an affected zlib version, and exposes the applicable MiniZip code through its compress API.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages30 packages

PyPIsmihica/pyminizip0.2.6
NVDzlib/zlib< 1.3.1
debiandebian/zlib< minizip 1.1-8+deb12u1 (bookworm)
debiandebian/minizip< minizip 1.1-8+deb12u1 (bookworm)

Patches

🔴Vulnerability Details

5
GHSA
Fiona affected by CVE-2023-45853 related to MiniZip madler-zlib2024-07-16
OSV
Fiona affected by CVE-2023-45853 related to MiniZip madler-zlib2024-07-16
OSV
CVE-2023-45853: MiniZip in zlib through 12023-10-14
GHSA
pyminizip affected by zlib's integer overflow/heap based buffer overflow vulnerability due to vulnerable dependency2023-10-14
OSV
pyminizip affected by zlib's integer overflow/heap based buffer overflow vulnerability due to vulnerable dependency2023-10-14

📋Vendor Advisories

8
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Outside In Search Export SDK (zlib) — CVE-2023-458532025-10-15
CISA ICS
Siemens SCALANCE W7002025-02-13
Ubuntu
zlib vulnerability2024-11-13
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: SSL Module (zlib) — CVE-2023-458532024-07-15
CISA ICS
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.12023-12-14

🕵️Threat Intelligence

4
Qualys
Oracle Critical Patch Update, October 2025 Security Update Review2025-10-23
Qualys
Oracle Critical Patch Update, October 2025 Security Update Review | Qualys2025-10-23
Qualys
Oracle Critical Patch Update, July 2024 Security Update Review2024-07-17
Qualys
Oracle Critical Patch Security Update: July 2024 Review | Qualys2024-07-17