Headline
GHSA-q5fm-55c2-v6j9: Fiona affected by CVE-2023-45853 related to MiniZip madler-zlib
Summary
Vulnerability scan of fiona shows CVE-2023-45853
Details
fiona depends on madler-zlib 1.3. MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field. NOTE: MiniZip is not a supported part of the zlib product. NOTE: pyminizip through 0.2.6 is also vulnerable because it bundles an affected zlib version, and exposes the applicable MiniZip code through its compress API.
Impact
Unkown. Please document if this vulnerability is exposed
Skip to content
Navigation Menu
Actions
Automate any workflow
Packages
Host and manage packages
Security
Find and fix vulnerabilities
Codespaces
Instant dev environments
GitHub Copilot
Write better code with AI
Code review
Manage code changes
Issues
Plan and track work
Discussions
Collaborate outside of code
Explore
- Learning Pathways
- White papers, Ebooks, Webinars
- Customer Stories
- Partners
GitHub Sponsors
Fund open source developers
* The ReadME Project
GitHub community articles
Enterprise platform
AI-powered developer platform
- Pricing
Provide feedback
Saved searches****Use saved searches to filter your results more quickly
Sign up
- GitHub Advisory Database
- GitHub Reviewed
- GHSA-q5fm-55c2-v6j9
Fiona affected by CVE-2023-45853 related to MiniZip madler-zlib
Critical severity GitHub Reviewed Published Jul 15, 2024 in Toblerity/Fiona • Updated Jul 16, 2024
Affected versions
< 1.10b1
Description
Summary
Vulnerability scan of fiona shows CVE-2023-45853
Details
fiona depends on madler-zlib 1.3. MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field. NOTE: MiniZip is not a supported part of the zlib product. NOTE: pyminizip through 0.2.6 is also vulnerable because it bundles an affected zlib version, and exposes the applicable MiniZip code through its compress API.
Impact
Unkown. Please document if this vulnerability is exposed
References
- GHSA-q5fm-55c2-v6j9
- https://nvd.nist.gov/vuln/detail/CVE-2023-45853
- OSGeo/gdal@4aa7ca6
- madler/zlib@73331a6
Published to the GitHub Advisory Database
Jul 16, 2024
Last updated
Jul 16, 2024