mirror of
https://github.com/jmcnamara/libxlsxwriter.git
synced 2026-05-15 14:15:54 -06:00
[PR #427] [MERGED] From zlib: Reject overflows of zip header fields in minizip. #490
Labels
No labels
awaiting user feedback
bug
cmake
cmake
docs
feature request
in progress
long term
medium term
medium term
pull-request
question
question
ready to close
short term
under investigation
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference: github-starred/libxlsxwriter#490
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
📋 Pull Request Information
Original PR: https://github.com/jmcnamara/libxlsxwriter/pull/427
Author: @jayaddison
Created: 12/24/2023
Status: ✅ Merged
Merged: 12/24/2023
Merged by: @jmcnamara
Base:
main← Head:security/CVE-2023-45853📝 Commits (1)
6aaf223Reject overflows of zip header fields in minizip.📊 Changes
1 file changed (+11 additions, -0 deletions)
View changed files
📝
third_party/minizip/zip.c(+11 -0)📄 Description
With the
minizipcode in the codebase updated by #420, it's fairly straightforward to cherry-pick a fixup for CVE-2023-45853.If-and-when a release of
zlibv1.3.1 (that containsminizipin thecontribdirectory) appears, it could be worthwhile to update to that; since that hasn't appeared yet I think it may make sense to apply this here directly.🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.