Intel

CVE-2023-45853

zlib is vulnerable to Remote code execution

Remote code execution Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Oct 14, 2023

98

Critical Risk

This Affects:

zlib
Are you affected? Scan for Free

TL;DR

Opening a ZIP file with zlib/MiniZip can result in remote code execution if the ZIP file can be provided by an attacker. The underlying mechanism is a buffer overflow.

Who does this affect?

If your app opens ZIP files that are uploaded by your users, you are affected.

Background info

zlib is vulnerable to Remote code execution in versions < 1.3.1.

How to fix this

Upgrade zlib to any version above 1.3.0 once it is released.