CVE-2023-45853
Critical · CVSS 9.8MiniZip / zlib / pyminizip — Integer overflow and heap-based buffer overflow in ZIP file creation (CWE-190)
- CVSS
- 9.8
- nvd
- EPSS
- 2.92%
- 85th pct
- KEV
- No
- Class
- oss containerizable
- CWE-190, CWE-190
Description
MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field. NOTE: MiniZip is not a supported part of the zlib product. NOTE: pyminizip through 0.2.6 is also vulnerable because it bundles an affected zlib version, and exposes the applicable MiniZip code through its compress API.
Search profile — drives PoC discovery
Ranked PoCs (58) — best first
Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.
- ★ 0
- ★ 0
- ★ 0
- ★ 0containerized · known researchertrickest
- ★ 0
- ★ 0
- ★ 0
- ★ 0
- ★ 0
- ★ 0
- ★ 0
- ★ 0
- ★ 0
- ★ 0
- ★ 0
- ★ 0
- ★ 0
- ★ 0
- ★ 0
- ★ 0
- ★ 0
- ★ 0
- ★ 0
- ★ 0ADILBENANI4/inventa needs reviewtrickest
- ★ 0AndewlCode/DevSecOps_Homework_7 needs reviewtrickest
- ★ 0Atamik03/API-calc-dz needs reviewtrickest
- ★ 0CKA-codespace/cg-compare needs reviewtrickest
- ★ 0ChrisAdkin8/Nomad-Job-Vulnerability-Tagging needs reviewtrickest
- ★ 0Dgporte/ExerciciosDockerPB2025 needs reviewtrickest
- ★ 0GrigGM/05-virt-04-docker-hw needs reviewtrickest
- ★ 0LuxenStudio/ml-garage needs reviewtrickest
- ★ 0MayurManjrekar/DevSecOps-Demo needs reviewtrickest
- ★ 0Metaller000/sib-ecommerce-diploma-report needs reviewtrickest
- ★ 0Myash-New/05-virt-04-docker-in-practice needs reviewtrickest
- ★ 0SCH227/own-research needs reviewtrickest
- ★ 0Telooss/TP-WIK-DPS-TP02 needs reviewtrickest
- ★ 0ZyntraAI/reader needs reviewtrickest
- ★ 0akabarki76/ideal-octo-meme needs reviewtrickest
- ★ 0bariskanber/zlib-1.3-deb needs reviewtrickest
- ★ 0bartvoet/assignment-ehb-security-review-adamlenez needs reviewtrickest
- ★ 0bygregonline/devsec-fastapi-report needs reviewtrickest
- ★ 0deficientrock/vexllm needs reviewtrickest
- ★ 0dnf475209865/-jina-ai needs reviewtrickest
- ★ 0drewtwitchell/scancompare needs reviewtrickest
- ★ 0fkie-cad/nvd-json-data-feeds needs reviewtrickest
- ★ 0hargup/reader needs reviewtrickest
- ★ 0luxenstudio-project/ml-garage needs reviewtrickest
- ★ 0marklogic/marklogic-kubernetes needs reviewtrickest
- ★ 0pluribus-one/mdr-ra needs reviewtrickest
- ★ 0poikl246/DevSecOps-2024-v2 needs reviewtrickest
- ★ 0robertsirc/sle-bci-demo needs reviewtrickest
- ★ 0runwhen-contrib/helm-charts needs reviewtrickest
- ★ 0shakyaraj9569/Documentation needs reviewtrickest
- ★ 0siddhesh-its/Helm-Chart-Vulnerability-Scanner needs reviewtrickest
- ★ 0siddheshengineer/Helm-Chart-Vulnerability-Scanner needs reviewtrickest
- ★ 0siddheshenginer/Helm-Chart-Vulnerability-Scanner needs reviewtrickest
- ★ 0telis-project/ml-garage needs reviewtrickest
- ★ 0vinicius-emanuelds/projeto-DevOps needs reviewtrickest
Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.
Affected packages
| PyPI | pyminizip | 0 → ∞ |
References
- http://www.openwall.com/lists/oss-security/2023/10/20/9
- http://www.openwall.com/lists/oss-security/2024/01/24/10
- https://chromium.googlesource.com/chromium/src/+/d709fb23806858847131027da95ef4c548813356
- https://chromium.googlesource.com/chromium/src/+/de29dd6c7151d3cd37cb4cf0036800ddfb1d8b61
- https://github.com/madler/zlib/blob/ac8f12c97d1afd9bafa9c710f827d40a407d3266/contrib/README.contrib#L1-L4
- https://github.com/madler/zlib/pull/843
- https://lists.debian.org/debian-lts-announce/2023/11/msg00026.html
- https://pypi.org/project/pyminizip/#history
- https://security.gentoo.org/glsa/202401-18
- https://security.netapp.com/advisory/ntap-20231130-0009/
- https://www.winimage.com/zLibDll/minizip.html
- http://www.openwall.com/lists/oss-security/2023/10/20/9
Status: enriched · ingested 2026-07-14T18:00:20.000Z · profiled 2026-07-14T18:30:20.000Z