MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field. NOTE: MiniZip is not a supported part of the zlib product. NOTE: pyminizip through 0.2.6 is also vulnerable because it bundles an affected zlib version, and exposes the applicable MiniZip code through its compress API.
{
"sources": [
{
"modified": "2024-12-20T17:41:31.237Z",
"database_specific": {
"status": "Analyzed"
},
"html_url": "https://nvd.nist.gov/vuln/detail/CVE-2023-45853",
"id": "CVE-2023-45853",
"imported": "2026-05-07T17:21:39.053Z",
"published": "2023-10-14T02:15:09.323Z",
"url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2023-45853"
}
],
"license": "CC-BY-4.0"
}