Xceed Zip for COM/ActiveX on x86/x64 Documentation
Security vulnerability reports / CVE-2023-45853
In This Topic
    CVE-2023-45853
    In This Topic

    Description

    MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field. NOTE: MiniZip is not a supported part of the zlib product. NOTE: pyminizip through 0.2.6 is also vulnerable because it bundles an affected zlib version, and exposes the applicable MiniZip code through its compress API.

    Timeline

    Vulnerable

    No.

    Remarks

    The component is not statically linked to any specific ZLib version. The MiniZip functions are not part of the component.

    See Also