CVE-2023-45853

Siemens ProductCERT Advisory SSA-398330

criticalEPSS 3.2%

Description

MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field. NOTE: MiniZip is not a supported part of the zlib product. NOTE: pyminizip through 0.2.6 is also vulnerable because it bundles an affected zlib version, and exposes the applicable MiniZip code through its compress API.

Metrics

Severity
critical
no public PoC known
9.8
Source: nvd-v3
87.3 %
Critical — this CVE ranks in the top fifth of all CVEs scored today (rank ≥ 80%).
3.2 %
Moderate — model estimates 1-10% exploitation likelihood.
Published
2022-03-15 17:05 UTC

Affected operating systems

  • linux

    debian / debian_linux10.0

  • linux

    debian / debian_linux11.0

  • linux

    debian / debian_linux9.0

  • linux

    ubuntu / linuxbionic

  • linux

    ubuntu / linux-awsbionic

  • linux

    ubuntu / linux-aws-fipsbionic

  • linux

    ubuntu / linux-azure-4.15bionic

  • linux

    ubuntu / linux-azure-fipsbionic

  • linux

    ubuntu / linux-fipsbionic

  • linux

    ubuntu / linux-gcp-4.15bionic

  • linux

    ubuntu / linux-gcp-fipsbionic

  • linux

    ubuntu / linux-kvmbionic

  • linux

    linux / linux_kernel6.10

  • linux

    linux / linux_kernel6.11

  • linux

    linux / linux_kernel6.12

  • linux

    linux / linux_kernel6.13

  • linux

    linux / linux_kernel6.9

  • linux

    linux / linux_kernel

  • linux

    ubuntu / opensslbionic

  • linux

    ubuntu / opensslfocal

  • linux

    ubuntu / openssltrusty

  • linux

    ubuntu / opensslxenial

  • linux

    ubuntu / openssl1.0bionic

  • macos

    apple / mac_os_x10.15.7

Affected products

Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.

  • android

    :linux_kernel::0

  • android

    :linux_kernel:Kernel

  • azul

    zulu

  • bitnami

    node-min12.0.0

  • bitnami

    node-min12.13.0

  • bitnami

    node-min14.0.0

  • bitnami

    node-min14.15.0

  • bitnami

    node-min16.0.0

  • bitnami

    node-min16.13.0

  • bitnami

    node-min17.0.0

  • Dell

    NetWorkerVirtual Edition

  • Dell

    NetWorkervProxy

  • Dell

    PowerProtect Data Domain7.10.1.70

  • Dell

    PowerProtect Data Domain7.13.1.40

  • Dell

    PowerProtect Data Domain8.3.1.10

  • Dell

    PowerProtect Data Domain8.4.0.0

  • Dell

    PowerProtect Data Domain< 7.10.1.70

    fixed in 7.10.1.70

  • Dell

    PowerProtect Data Domain< 7.13.1.40

    fixed in 7.13.1.40

  • Dell

    PowerProtect Data Domain< 8.3.1.10

    fixed in 8.3.1.10

  • Dell

    PowerProtect Data Domain< 8.4.0.0

    fixed in 8.4.0.0

  • goto

    gotoassist11.9.18

  • HPE

    HP-UXOpenSSL Software <A.03.00.15.001

  • IBM

    AIX7.2

  • IBM

    AIX7.3

References & sources

Linked CVEs

Show 37 more CVEs
IDCVE-2023-45853