Intel

CVE-2023-45853

zlib is vulnerable to Remote code execution

Remote code execution Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Oct 14, 2023

98

Critical Risk

This Affects:

zlib
Are you affected? Scan for Free

TL;DR

Opening a ZIP file with zlib/MiniZip can result in remote code execution if the ZIP file can be provided by an attacker. The underlying mechanism is a buffer overflow.

Who does this affect?

If your app opens ZIP files that are uploaded by your users, you are affected.

Background info

zlib is vulnerable to Remote code execution in versions < 1.3.1.

How to fix this

Upgrade zlib to any version above 1.3.0 once it is released.

Links

Other

openwall.com/lists/oss-security/2023/10/20/9
http://www.openwall.com/lists/oss-security/2023/10/20/9
openwall.com/lists/oss-security/2024/01/24/10
http://www.openwall.com/lists/oss-security/2024/01/24/10
chromium.googlesource.com/chromium/src/+/d709fb23806858847131027da95ef4c548813356
https://chromium.googlesource.com/chromium/src/+/d709fb23806858847131027da95ef4c548813356
chromium.googlesource.com/chromium/src/+/de29dd6c7151d3cd37cb4cf0036800ddfb1d8b61
https://chromium.googlesource.com/chromium/src/+/de29dd6c7151d3cd37cb4cf0036800ddfb1d8b61
github.com/madler/zlib/blob/ac8f12c97d1afd9bafa9c710f827d40a407d3266/contrib/README.contrib#L1-L4
https://github.com/madler/zlib/blob/ac8f12c97d1afd9bafa9c710f827d40a407d3266/contrib/README.contrib#L1-L4
lists.debian.org/debian-lts-announce/2023/11/msg00026.html
https://lists.debian.org/debian-lts-announce/2023/11/msg00026.html
pypi.org/project/pyminizip/#history
https://pypi.org/project/pyminizip/#history
security.gentoo.org/glsa/202401-18
https://security.gentoo.org/glsa/202401-18
security.netapp.com/advisory/ntap-20231130-0009/
https://security.netapp.com/advisory/ntap-20231130-0009/
winimage.com/zLibDll/minizip.html
https://www.winimage.com/zLibDll/minizip.html
cert-portal.siemens.com/productcert/html/ssa-398330.html
https://cert-portal.siemens.com/productcert/html/ssa-398330.html
cert-portal.siemens.com/productcert/html/ssa-470355.html
https://cert-portal.siemens.com/productcert/html/ssa-470355.html
cert-portal.siemens.com/productcert/html/ssa-769027.html
https://cert-portal.siemens.com/productcert/html/ssa-769027.html