Heap-based buffer overflow in Zlib - CVE-2023-45853
Published: October 23, 2023
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error within the zipOpenNewFileInZip4_64() function from MiniZip. A remote attacker can create a specially crafted archive, trick the victim into opening it, trigger heap-based buffer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Amazon Linux AMI
Gentoo Linux
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Software Development Kit 12
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
openSUSE Leap Micro
Ubuntu
Development Tools Module
Basesystem Module
openSUSE Leap
openEuler
Anolis OS
IBM InfoSphere Information Server
IBM DB2
Telemetry Dashboard
IBM Watson Machine Learning Accelerator
DataStage on Cloud Pak for Data
Liquidware
Db2 Big SQL
IBM OpenPages with Watson
Datacap
Citrix Workspace App
Webex App VDI
ObjectScale
Cognos Dashboards on Cloud Pak for Data
Storage Protect Server
Integration Bus for z/OS
Live Optics Linux Collector
Live Optics Windows Collector
IBM OmniFind Text Search Server for DB2 for i
IBM Security Guardium Key Lifecycle Manager (GKLM)
WebSphere Remote Server
IBM Security Verify Governance
Tenable Nessus
Oracle HTTP Server
IBM Tivoli Business Service Manager
IBM Cloud Application Performance Management (APM)
PowerProtect Data Manager
IBM Cloud Pak for Business Automation
LANTIME Operating System Firmware (LTOS)
BIG-IP
BIG-IQ Centralized Management
Oracle Outside In Technology
Nessus Agent
Cisco Jabber
Cisco Webex Meetings
VMware Horizon Client
zlib-bin (Ubuntu package)
libx32z1-dev (Ubuntu package)
libx32z1 (Ubuntu package)
lib32z1-dev (Ubuntu package)
lib32z1 (Ubuntu package)
zlib1g (Ubuntu package)
zlib1g-dev (Ubuntu package)
libz1-32bit
libz1-debuginfo-32bit
zlib-devel-static
zlib-debugsource
zlib-devel
zlib-devel-32bit
libz1
libz1-debuginfo
zlib-help
zlib
minizip
zlib-debuginfo
minizip-devel
libminizip1
libminizip1-debuginfo
libz1-32bit-debuginfo
libminizip1-32bit
zlib-devel-static-32bit
libminizip1-32bit-debuginfo
sys-libs/zlib
minizip-compat
minizip-compat-devel
zlib-static
zlib-doc
zlib-testsuite-debuginfo
zlib-testsuite
libz1-64bit-debuginfo
zlib-devel-64bit
libminizip1-64bit
libminizip1-64bit-debuginfo
zlib-devel-static-64bit
libz1-64bit
IBM Cloud Pak System
JBoss Core Services
IBM FileNet Content Manager
Dell EMC VxRail Appliance
IBM App Connect Enterprise
Dell EMC NetWorker vProxy
How to mitigate CVE-2023-45853
IBM Watson Machine Learning Accelerator - update to 5.0.3
DataStage on Cloud Pak for Data - update to 5.2.1
Liquidware - update to 6.7.0.2.2 on Thin OS 2405
LANTIME Operating System Firmware (LTOS) - update to 7.08.009
Db2 Big SQL - update to 7.6.8
Nessus Agent - update to 10.4.3
Tenable Nessus - update to 10.6.2
Cisco Jabber - update to 14.3.0.308378.11 on Thin OS 2405
Citrix Workspace App - update to 24.2.0.65.17 on Thin OS 2405
Webex App VDI - update to 44.2.0.28744.1 on Thin OS 2405
Cisco Webex Meetings - update to 44.2.0.76.2 on Thin OS 2405
VMware Horizon Client - update to 2312.1.8.12.1.5 on Thin OS 2405
zlib-bin (Ubuntu package) - update to Ubuntu Pro
libx32z1-dev (Ubuntu package) - update to Ubuntu Pro
libx32z1 (Ubuntu package) - update to Ubuntu Pro
lib32z1-dev (Ubuntu package) - update to Ubuntu Pro
lib32z1 (Ubuntu package) - update to Ubuntu Pro
zlib1g (Ubuntu package) - update to Ubuntu Pro
zlib1g-dev (Ubuntu package) - update to Ubuntu Pro
libz1-32bit - addressed in versions 1.2.11-11.37.1, 1.2.11-150000.3.48.1, 1.2.13-150500.4.3.1
libz1-debuginfo-32bit - update to 1.2.11-11.37.1
zlib-devel-static - addressed in versions 1.2.11-11.37.1, 1.2.11-150000.3.48.1, 1.2.13-150500.4.3.1
zlib-debugsource - addressed in versions 1.2.11-11.37.1, 1.2.11-150000.3.48.1, 1.2.13-150500.4.3.1
zlib-devel - addressed in versions 1.2.11-11.37.1, 1.2.11-150000.3.48.1, 1.2.13-150500.4.3.1
zlib-devel-32bit - addressed in versions 1.2.11-11.37.1, 1.2.11-150000.3.48.1, 1.2.13-150500.4.3.1
libz1 - addressed in versions 1.2.11-11.37.1, 1.2.11-150000.3.48.1, 1.2.13-150500.4.3.1
libz1-debuginfo - addressed in versions 1.2.11-11.37.1, 1.2.11-150000.3.48.1, 1.2.13-150500.4.3.1
zlib-help - update to 1.2.11-22
zlib - update to 1.2.11-22
minizip - update to 1.2.11-22
zlib-debuginfo - update to 1.2.11-22
zlib-devel - update to 1.2.11-22
zlib-debugsource - update to 1.2.11-22
minizip-devel - update to 1.2.11-22
zlib - update to 1.2.11-33
libminizip1 - addressed in versions 1.2.11-150000.3.48.1, 1.2.13-150500.4.3.1
minizip-devel - addressed in versions 1.2.11-150000.3.48.1, 1.2.13-150500.4.3.1
libminizip1-debuginfo - addressed in versions 1.2.11-150000.3.48.1, 1.2.13-150500.4.3.1
libz1-32bit-debuginfo - addressed in versions 1.2.11-150000.3.48.1, 1.2.13-150500.4.3.1
libminizip1-32bit - addressed in versions 1.2.11-150000.3.48.1, 1.2.13-150500.4.3.1
zlib-devel-static-32bit - addressed in versions 1.2.11-150000.3.48.1, 1.2.13-150500.4.3.1
libminizip1-32bit-debuginfo - addressed in versions 1.2.11-150000.3.48.1, 1.2.13-150500.4.3.1
sys-libs/zlib - update to 1.2.13-r2
minizip-compat - update to 1.2.13-2
minizip-compat-devel - update to 1.2.13-2
zlib - update to 1.2.13-2
zlib-devel - update to 1.2.13-2
zlib-static - update to 1.2.13-2
zlib-doc - update to 1.2.13-2
zlib-testsuite-debuginfo - update to 1.2.13-150500.4.3.1
zlib-testsuite - update to 1.2.13-150500.4.3.1
libz1-64bit-debuginfo - update to 1.2.13-150500.4.3.1
zlib-devel-64bit - update to 1.2.13-150500.4.3.1
libminizip1-64bit - update to 1.2.13-150500.4.3.1
libminizip1-64bit-debuginfo - update to 1.2.13-150500.4.3.1
zlib-devel-static-64bit - update to 1.2.13-150500.4.3.1
libz1-64bit - update to 1.2.13-150500.4.3.1
ObjectScale - update to 1.4.0
IBM Cloud Pak System - addressed in versions 2.3.4.1, 2.3.5.0
JBoss Core Services - update to 2.4.57 SP2
Cognos Dashboards on Cloud Pak for Data - addressed in versions 4.8.9, 5.1.3
IBM FileNet Content Manager - addressed in versions 5.5.8.0 IF009, 5.5.12.0 IF004, 5.6.0.0 IF002
IBM Tivoli Business Service Manager - update to 6.2.0.5.5
Dell EMC VxRail Appliance - update to 8.0.201
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.4
Storage Protect Server - update to 8.1.24
Integration Bus for z/OS - update to 10.1.0.3
IBM DB2 - addressed in versions 10.5 FP11, 11.1.4.7
IBM App Connect Enterprise - addressed in versions 11.0.0.24, 12.0.10.1
Dell EMC NetWorker vProxy - addressed in versions 19.9.0.4, 19.10
PowerProtect Data Manager - update to 19.19.0-15
IBM Cloud Pak for Business Automation - addressed in versions 24.0.0-IF004, 24.0.1-IF001
Live Optics Linux Collector - update to 25.2.2.30
Live Optics Windows Collector - update to 25.2.2.154
External References
- https://www.winimage.com/zLibDll/minizip.html
- https://github.com/madler/zlib/pull/843
- https://chromium.googlesource.com/chromium/src/+/d709fb23806858847131027da95ef4c548813356
- https://chromium.googlesource.com/chromium/src/+/de29dd6c7151d3cd37cb4cf0036800ddfb1d8b61
- https://github.com/madler/zlib/blob/ac8f12c97d1afd9bafa9c710f827d40a407d3266/contrib/README.contrib#L1-L4
- http://www.openwall.com/lists/oss-security/2023/10/20/9
Related Security Bulletins
- Remote code execution in zlib
- SUSE update for zlib
- SUSE update for zlib
- SUSE update for zlib
- Multiple vulnerabilities in Tenable Nessus 10.6
- Multiple vulnerabilities in Tenable Nessus Agent
- Multiple vulnerabilities in Red Hat JBoss Core Services Apache HTTP Server 2.4
- Gentoo update for zlib
- Dell EMC NetWorker vProxy update for third-party components
- Heap-based buffer overflow in IBM InfoSphere Information Server
- Heap-based buffer overflow in IBM App Connect Enterprise and IBM Integration Bus for z/OS
- openEuler update for zlib
- Heap-based buffer overflow in Dell Live Optics Collector
- Multiple vulnerabilities in Dell ThinOS
- Heap-based buffer overflow in IBM Db2
- Multiple vulnerabilities in Oracle Outside In Technology
- Multiple vulnerabilities in Oracle HTTP Server
- Multiple vulnerabilities in IBM WebSphere Remote Server
- Multiple vulnerabilities in IBM Cloud APM
- Multiple vulnerabilities in Dell ObjectScale
- Multiple vulnerabilities in IBM OpenPages with Watson
- Multiple vulnerabilities in IBM Security Guardium Key Lifecycle Manager
- Multiple vulnerabilities in IBM Security Verify Governance
- Multiple vulnerabilities in Datacap
- Multiple vulnerabilities in IBM Tivoli Business Service Manager
- Multiple vulnerabilities in IBM Storage Protect Server
- Multiple vulnerabilities in IBM Cloud Pak System
- Ubuntu update for zlib
- Amazon Linux AMI update for zlib
- Buffer overflow in F5 BIG-IP MiniZip component
- Buffer overflow in F5 BIG-IQ Centralized Management MiniZip component
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation
- Multiple vulnerabilities in IBM FileNet Content Manager
- Anolis OS update for zlib
- Multiple vulnerabilities in Dell EMC VxRail Appliance
- Multiple vulnerabilities in Dell PowerProtect Data Manager
- Multiple vulnerabilities in IBM Cognos Dashboards on Cloud Pak for Data
- Meinberg LANTIME firmware update for third-party components (February 2024)
- IBM DataStage on Cloud Pak for Data update for MiniZip
- Multiple vulnerabilities in Oracle Outside In Technology
- Multiple vulnerabilities in IBM Big SQL on IBM Cloud Pak for Data
- Multiple vulnerabilities in IBM Watson Machine Learning Accelerator on Cloud Pak for Data
- Multiple vulnerabilities in IBM OmniFind Text Search Server for DB2 for i