CVE-2023-45853
ADVISORY - githubSummary
MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field. NOTE: MiniZip is not a supported part of the zlib product.
pyminizip uses version 1.2.11 of zlib's code.
EPSS Score: 0.00382 (0.587)
Common Weakness Enumeration (CWE)
ADVISORY - nist
Integer Overflow or Wraparound
ADVISORY - github
Integer Overflow or Wraparound
ADVISORY - gitlab
Sign in to Docker Scout
See which of your images are affected by this CVE and how to fix them by signing into Docker Scout.
Sign in