QID 996366

Date Published: 2023-12-19

QID 996366: Python (Pip) Security Update for pyminizip (GHSA-mq29-j5xf-cjwr)

MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field. NOTE: MiniZip is not a supported part of the zlib product.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Refer to Github security advisory GHSA-mq29-j5xf-cjwr for updates and patch information.
    Vendor References

    CVEs related to QID 996366

    Software Advisories
    Advisory ID Software Component Link