MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field. NOTE: MiniZip is not a supported part of the zlib product. NOTE: pyminizip through 0.2.6 is also vulnerable because it bundles an affected zlib version, and exposes the applicable MiniZip code through its compress API.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/45xxx/CVE-2023-45853.json",
"cna_assigner": "mitre",
"unresolved_ranges": [
{
"extracted_events": [
{
"fixed": "0.2.6"
}
],
"source": "DESCRIPTION"
}
]
}[
{
"digest": {
"line_hashes": [
"133323228423686030849250076604700952651",
"241781128640873773847102295658824061194",
"26300387571939795497803882545891538835"
],
"threshold": 0.9
},
"id": "CVE-2023-45853-84b1068e",
"signature_version": "v1",
"target": {
"file": "deflate.c"
},
"deprecated": false,
"signature_type": "Line",
"source": "https://github.com/madler/zlib/commit/09155eaa2f9270dc4ed1fa13e2b4b2613e6e4851"
},
{
"digest": {
"line_hashes": [
"30376754175980397137245385213038828735",
"222033311297963817506721545632955611436",
"264539535648468080285645399968831115354",
"93795520909171586436363295225242129037",
"232747036040056526295022693236988506702",
"136413305281236666932798501035662291853",
"180248738468867346446154357880424280323",
"187568885583340518721432656319992010175"
],
"threshold": 0.9
},
"id": "CVE-2023-45853-89024b3d",
"signature_version": "v1",
"target": {
"file": "contrib/infback9/inftree9.c"
},
"deprecated": false,
"signature_type": "Line",
"source": "https://github.com/madler/zlib/commit/09155eaa2f9270dc4ed1fa13e2b4b2613e6e4851"
},
{
"digest": {
"line_hashes": [
"206349224317579752565365369565167588261",
"304161426365440726211758156798093709819",
"186418906060129989093132384098485718328",
"209926081733718815288688060140014850580",
"95988406633891284077118636514685324039",
"116529096759194607238340463980486817705",
"169191686664871664285399934938784645776",
"105353330407596822014156806522996998001"
],
"threshold": 0.9
},
"id": "CVE-2023-45853-b9bffb00",
"signature_version": "v1",
"target": {
"file": "inftrees.c"
},
"deprecated": false,
"signature_type": "Line",
"source": "https://github.com/madler/zlib/commit/09155eaa2f9270dc4ed1fa13e2b4b2613e6e4851"
}
]
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-45853.json"
"2026-05-31T00:26:22Z"