​
DirectorySecurity Advisories
Sign In
Security Advisories

CGA-jq67-276v-crw8

Published

Last updated

https://images.chainguard.dev/security/CGA-jq67-276v-crw8
Package

zlib

Latest Update
Fixed
Fixed Version

1.3-r1

Aliases
  • CVE-2023-45853
  • GHSA-mq29-j5xf-cjwr

Severity

9.8

Critical

CVSS V3

Summary

pyminizip affected by zlib's integer overflow/heap based buffer overflow vulnerability due to vulnerable dependency

Description

MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field. NOTE: MiniZip is not a supported part of the zlib product.

pyminizip uses version 1.2.11 of zlib's code.

References

Updates


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images