Heap-based buffer overflow in Zlib - CVE-2023-45853

 

Heap-based buffer overflow in Zlib - CVE-2023-45853

Published: October 23, 2023


Vulnerability identifier: #VU82299
CSH Severity: Medium
CVSS v4: 7.5 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-45853
CWE-ID: CWE-122
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error within the zipOpenNewFileInZip4_64() function from MiniZip. A remote attacker can create a specially crafted archive, trick the victim into opening it, trigger heap-based buffer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

Zlib
Amazon Linux AMI
Gentoo Linux
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Software Development Kit 12
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
openSUSE Leap Micro
Ubuntu
Development Tools Module
Basesystem Module
openSUSE Leap
openEuler
Anolis OS
IBM InfoSphere Information Server
IBM DB2
Telemetry Dashboard
IBM Watson Machine Learning Accelerator
DataStage on Cloud Pak for Data
Liquidware
Db2 Big SQL
IBM OpenPages with Watson
Datacap
Citrix Workspace App
Webex App VDI
ObjectScale
Cognos Dashboards on Cloud Pak for Data
Storage Protect Server
Integration Bus for z/OS
Live Optics Linux Collector
Live Optics Windows Collector
IBM OmniFind Text Search Server for DB2 for i
IBM Security Guardium Key Lifecycle Manager (GKLM)
WebSphere Remote Server
IBM Security Verify Governance
Tenable Nessus
Oracle HTTP Server
IBM Tivoli Business Service Manager
IBM Cloud Application Performance Management (APM)
PowerProtect Data Manager
IBM Cloud Pak for Business Automation
LANTIME Operating System Firmware (LTOS)
BIG-IP
BIG-IQ Centralized Management
Oracle Outside In Technology
Nessus Agent
Cisco Jabber
Cisco Webex Meetings
VMware Horizon Client
zlib-bin (Ubuntu package)
libx32z1-dev (Ubuntu package)
libx32z1 (Ubuntu package)
lib32z1-dev (Ubuntu package)
lib32z1 (Ubuntu package)
zlib1g (Ubuntu package)
zlib1g-dev (Ubuntu package)
libz1-32bit
libz1-debuginfo-32bit
zlib-devel-static
zlib-debugsource
zlib-devel
zlib-devel-32bit
libz1
libz1-debuginfo
zlib-help
zlib
minizip
zlib-debuginfo
minizip-devel
libminizip1
libminizip1-debuginfo
libz1-32bit-debuginfo
libminizip1-32bit
zlib-devel-static-32bit
libminizip1-32bit-debuginfo
sys-libs/zlib
minizip-compat
minizip-compat-devel
zlib-static
zlib-doc
zlib-testsuite-debuginfo
zlib-testsuite
libz1-64bit-debuginfo
zlib-devel-64bit
libminizip1-64bit
libminizip1-64bit-debuginfo
zlib-devel-static-64bit
libz1-64bit
IBM Cloud Pak System
JBoss Core Services
IBM FileNet Content Manager
Dell EMC VxRail Appliance
IBM App Connect Enterprise
Dell EMC NetWorker vProxy

How to mitigate CVE-2023-45853

Install update from vendor's website.

Telemetry Dashboard - update to 1.1.0.6 on Thin OS 2405
IBM Watson Machine Learning Accelerator - update to 5.0.3
DataStage on Cloud Pak for Data - update to 5.2.1
Liquidware - update to 6.7.0.2.2 on Thin OS 2405
LANTIME Operating System Firmware (LTOS) - update to 7.08.009
Db2 Big SQL - update to 7.6.8
Nessus Agent - update to 10.4.3
Tenable Nessus - update to 10.6.2
Cisco Jabber - update to 14.3.0.308378.11 on Thin OS 2405
Citrix Workspace App - update to 24.2.0.65.17 on Thin OS 2405
Webex App VDI - update to 44.2.0.28744.1 on Thin OS 2405
Cisco Webex Meetings - update to 44.2.0.76.2 on Thin OS 2405
VMware Horizon Client - update to 2312.1.8.12.1.5 on Thin OS 2405
zlib-bin (Ubuntu package) - update to Ubuntu Pro
libx32z1-dev (Ubuntu package) - update to Ubuntu Pro
libx32z1 (Ubuntu package) - update to Ubuntu Pro
lib32z1-dev (Ubuntu package) - update to Ubuntu Pro
lib32z1 (Ubuntu package) - update to Ubuntu Pro
zlib1g (Ubuntu package) - update to Ubuntu Pro
zlib1g-dev (Ubuntu package) - update to Ubuntu Pro
libz1-32bit - addressed in versions 1.2.11-11.37.1, 1.2.11-150000.3.48.1, 1.2.13-150500.4.3.1
libz1-debuginfo-32bit - update to 1.2.11-11.37.1
zlib-devel-static - addressed in versions 1.2.11-11.37.1, 1.2.11-150000.3.48.1, 1.2.13-150500.4.3.1
zlib-debugsource - addressed in versions 1.2.11-11.37.1, 1.2.11-150000.3.48.1, 1.2.13-150500.4.3.1
zlib-devel - addressed in versions 1.2.11-11.37.1, 1.2.11-150000.3.48.1, 1.2.13-150500.4.3.1
zlib-devel-32bit - addressed in versions 1.2.11-11.37.1, 1.2.11-150000.3.48.1, 1.2.13-150500.4.3.1
libz1 - addressed in versions 1.2.11-11.37.1, 1.2.11-150000.3.48.1, 1.2.13-150500.4.3.1
libz1-debuginfo - addressed in versions 1.2.11-11.37.1, 1.2.11-150000.3.48.1, 1.2.13-150500.4.3.1
zlib-help - update to 1.2.11-22
zlib - update to 1.2.11-22
minizip - update to 1.2.11-22
zlib-debuginfo - update to 1.2.11-22
zlib-devel - update to 1.2.11-22
zlib-debugsource - update to 1.2.11-22
minizip-devel - update to 1.2.11-22
zlib - update to 1.2.11-33
libminizip1 - addressed in versions 1.2.11-150000.3.48.1, 1.2.13-150500.4.3.1
minizip-devel - addressed in versions 1.2.11-150000.3.48.1, 1.2.13-150500.4.3.1
libminizip1-debuginfo - addressed in versions 1.2.11-150000.3.48.1, 1.2.13-150500.4.3.1
libz1-32bit-debuginfo - addressed in versions 1.2.11-150000.3.48.1, 1.2.13-150500.4.3.1
libminizip1-32bit - addressed in versions 1.2.11-150000.3.48.1, 1.2.13-150500.4.3.1
zlib-devel-static-32bit - addressed in versions 1.2.11-150000.3.48.1, 1.2.13-150500.4.3.1
libminizip1-32bit-debuginfo - addressed in versions 1.2.11-150000.3.48.1, 1.2.13-150500.4.3.1
sys-libs/zlib - update to 1.2.13-r2
minizip-compat - update to 1.2.13-2
minizip-compat-devel - update to 1.2.13-2
zlib - update to 1.2.13-2
zlib-devel - update to 1.2.13-2
zlib-static - update to 1.2.13-2
zlib-doc - update to 1.2.13-2
zlib-testsuite-debuginfo - update to 1.2.13-150500.4.3.1
zlib-testsuite - update to 1.2.13-150500.4.3.1
libz1-64bit-debuginfo - update to 1.2.13-150500.4.3.1
zlib-devel-64bit - update to 1.2.13-150500.4.3.1
libminizip1-64bit - update to 1.2.13-150500.4.3.1
libminizip1-64bit-debuginfo - update to 1.2.13-150500.4.3.1
zlib-devel-static-64bit - update to 1.2.13-150500.4.3.1
libz1-64bit - update to 1.2.13-150500.4.3.1
ObjectScale - update to 1.4.0
IBM Cloud Pak System - addressed in versions 2.3.4.1, 2.3.5.0
JBoss Core Services - update to 2.4.57 SP2
Cognos Dashboards on Cloud Pak for Data - addressed in versions 4.8.9, 5.1.3
IBM FileNet Content Manager - addressed in versions 5.5.8.0 IF009, 5.5.12.0 IF004, 5.6.0.0 IF002
IBM Tivoli Business Service Manager - update to 6.2.0.5.5
Dell EMC VxRail Appliance - update to 8.0.201
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.4
Storage Protect Server - update to 8.1.24
Integration Bus for z/OS - update to 10.1.0.3
IBM DB2 - addressed in versions 10.5 FP11, 11.1.4.7
IBM App Connect Enterprise - addressed in versions 11.0.0.24, 12.0.10.1
Dell EMC NetWorker vProxy - addressed in versions 19.9.0.4, 19.10
PowerProtect Data Manager - update to 19.19.0-15
IBM Cloud Pak for Business Automation - addressed in versions 24.0.0-IF004, 24.0.1-IF001
Live Optics Linux Collector - update to 25.2.2.30
Live Optics Windows Collector - update to 25.2.2.154

External References

Related Security Bulletins