{"schema_version":"1.9.0","id":"CVE-2023-45853","published":"2023-10-14T00:00:00Z","modified":"2026-08-12T14:51:16.762049Z","aliases":["GHSA-mq29-j5xf-cjwr","PYSEC-2026-501"],"related":["CGA-9342-5wj4-m9vw","SUSE-SU-2023:4215-1","SUSE-SU-2023:4216-1","SUSE-SU-2023:4217-1","SUSE-SU-2024:2431-1","SUSE-SU-2026:20659-1","SUSE-SU-2026:20709-1","SUSE-SU-2026:21013-1","SUSE-SU-2026:21151-1","openSUSE-SU-2024:13363-1","openSUSE-SU-2024:13462-1","openSUSE-SU-2025:14857-1","openSUSE-SU-2026:20487-1"],"details":"MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field. NOTE: MiniZip is not a supported part of the zlib product. NOTE: pyminizip through 0.2.6 is also vulnerable because it bundles an affected zlib version, and exposes the applicable MiniZip code through its compress API.","affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/madler/zlib","events":[{"introduced":"0"},{"fixed":"09155eaa2f9270dc4ed1fa13e2b4b2613e6e4851"}],"database_specific":{"cpe":"cpe:2.3:a:zlib:zlib:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"1.3"},{"fixed":"1.3.1"}],"source":["DESCRIPTION","CPE_RANGE"]}}],"versions":["v1.2.13","v1.2.12","v1.2.11","v1.2.10","v1.2.9","v1.2.8","v1.2.7.3","v1.2.7.2","v1.2.7.1","v1.2.7","v1.2.6.1","v1.2.6","v1.2.5.3","v1.2.5.2","v1.2.5.1","v1.2.5","v1.2.4.5","v1.2.4.4","v1.2.4.3","v1.2.4.2","v1.2.4.1","v1.2.4","v1.2.4-pre2","v1.2.4-pre1","v1.2.3.9","v1.2.3.8","v1.2.3.7","v1.2.3.6","v1.2.3.5","v1.2.3.4","v1.2.3.3","v1.2.3.2","v1.2.3.1","v1.2.3","v1.2.2.4","v1.2.2.3","v1.2.2.2","v1.2.2.1","v1.2.2","v1.2.1.2","v1.2.1.1","v1.2.1","v1.2.0.8","v1.2.0.7","v1.2.0.6","v1.2.0.5","v1.2.0.4","v1.2.0.3","v1.2.0.2","v1.2.0.1","v1.2.0","v1.1.4","v1.1.3","v1.1.2","v1.1.1","v1.1.0","v1.0.9","v1.0.8","v1.0.7","v1.0.5","v1.0.4","v1.0.2","v1.0.1","v1.0-pre","v0.99","v0.95","v0.94","v0.93","v0.92","v0.91","v0.9","v0.8","v0.79","v0.71"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-45853.json","vanir_signatures":[{"deprecated":false,"digest":{"line_hashes":["133323228423686030849250076604700952651","241781128640873773847102295658824061194","26300387571939795497803882545891538835"],"threshold":0.9},"id":"CVE-2023-45853-84b1068e","signature_type":"Line","signature_version":"v1","source":"https://github.com/madler/zlib/commit/09155eaa2f9270dc4ed1fa13e2b4b2613e6e4851","target":{"file":"deflate.c"}},{"deprecated":false,"digest":{"line_hashes":["30376754175980397137245385213038828735","222033311297963817506721545632955611436","264539535648468080285645399968831115354","93795520909171586436363295225242129037","232747036040056526295022693236988506702","136413305281236666932798501035662291853","180248738468867346446154357880424280323","187568885583340518721432656319992010175"],"threshold":0.9},"id":"CVE-2023-45853-89024b3d","signature_type":"Line","signature_version":"v1","source":"https://github.com/madler/zlib/commit/09155eaa2f9270dc4ed1fa13e2b4b2613e6e4851","target":{"file":"contrib/infback9/inftree9.c"}},{"deprecated":false,"digest":{"line_hashes":["206349224317579752565365369565167588261","304161426365440726211758156798093709819","186418906060129989093132384098485718328","209926081733718815288688060140014850580","95988406633891284077118636514685324039","116529096759194607238340463980486817705","169191686664871664285399934938784645776","105353330407596822014156806522996998001"],"threshold":0.9},"id":"CVE-2023-45853-b9bffb00","signature_type":"Line","signature_version":"v1","source":"https://github.com/madler/zlib/commit/09155eaa2f9270dc4ed1fa13e2b4b2613e6e4851","target":{"file":"inftrees.c"}}],"vanir_signatures_modified":"2026-08-12T14:51:16Z"}}],"references":[{"type":"WEB","url":"https://cert-portal.siemens.com/productcert/html/ssa-398330.html"},{"type":"WEB","url":"https://cert-portal.siemens.com/productcert/html/ssa-470355.html"},{"type":"WEB","url":"https://cert-portal.siemens.com/productcert/html/ssa-769027.html"},{"type":"WEB","url":"https://chromium.googlesource.com/chromium/src/+/d709fb23806858847131027da95ef4c548813356"},{"type":"WEB","url":"https://chromium.googlesource.com/chromium/src/+/de29dd6c7151d3cd37cb4cf0036800ddfb1d8b61"},{"type":"WEB","url":"https://github.com/madler/zlib/blob/ac8f12c97d1afd9bafa9c710f827d40a407d3266/contrib/README.contrib#L1-L4"},{"type":"WEB","url":"https://www.winimage.com/zLibDll/minizip.html"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/45xxx/CVE-2023-45853.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-45853"},{"type":"ADVISORY","url":"https://security.gentoo.org/glsa/202401-18"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20231130-0009/"},{"type":"FIX","url":"https://github.com/madler/zlib/pull/843"},{"type":"PACKAGE","url":"https://pypi.org/project/pyminizip/#history"},{"type":"ARTICLE","url":"http://www.openwall.com/lists/oss-security/2023/10/20/9"},{"type":"ARTICLE","url":"http://www.openwall.com/lists/oss-security/2024/01/24/10"},{"type":"ARTICLE","url":"https://lists.debian.org/debian-lts-announce/2023/11/msg00026.html"}],"database_specific":{"cna_assigner":"mitre","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/45xxx/CVE-2023-45853.json","unresolved_ranges":[{"extracted_events":[{"fixed":"0.2.6"}],"source":"DESCRIPTION"}]},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}