You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field. NOTE: MiniZip is not a supported part of the zlib product. NOTE: pyminizip through 0.2.6 is also vulnerable because it bundles an affected zlib version, and exposes the applicable MiniZip code through its compress API.
mend-for-github-combot
changed the title
CVE-2023-45853 (Medium) detected in boostboost_1_70_0-unsupported-bin-msvc-all-32-64
CVE-2023-45853 (High) detected in boostboost_1_70_0-unsupported-bin-msvc-all-32-64
Oct 16, 2023
mend-for-github-combot
changed the title
CVE-2023-45853 (High) detected in boostboost_1_70_0-unsupported-bin-msvc-all-32-64
CVE-2023-45853 (Critical) detected in boostboost_1_70_0-unsupported-bin-msvc-all-32-64
Oct 19, 2023
CVE-2023-45853 - Critical Severity Vulnerability
Vulnerable Library - boostboost_1_70_0-unsupported-bin-msvc-all-32-64
Free peer-reviewed portable C++ source libraries
Library home page: https://sourceforge.net/projects/boost/
Found in HEAD commit: 30207a8f9a2b5d0b116c65f1e59dfdeba6de5c3e
Found in base branch: main
Vulnerable Source Files (1)
/edrav2/eprj/boost/libs/beast/test/extern/zlib-1.2.11/contrib/minizip/zip.c
Vulnerability Details
MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field. NOTE: MiniZip is not a supported part of the zlib product. NOTE: pyminizip through 0.2.6 is also vulnerable because it bundles an affected zlib version, and exposes the applicable MiniZip code through its compress API.
Publish Date: 2023-10-14
URL: CVE-2023-45853
CVSS 3 Score Details (9.8)
Base Score Metrics:
Suggested Fix
Type: Upgrade version
Origin: https://security-tracker.debian.org/tracker/CVE-2023-45853
Release Date: 2023-10-14
Fix Resolution: v1.3.1
The text was updated successfully, but these errors were encountered: