{"id":"GHSA-q5fm-55c2-v6j9","aliases":[],"url":"https://o3.security/vulnerability/GHSA-q5fm-55c2-v6j9","summary":"Fiona affected by CVE-2023-45853 related to MiniZip madler-zlib","details":"### Summary\nVulnerability scan of fiona shows [CVE-2023-45853](https://nvd.nist.gov/vuln/detail/CVE-2023-45853). The vulnerability is in GDAL, a dependency of fiona.\n\n### Details\nFiona depends on GDAL and GDAL has a port of minizip. MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field. The GDAL project has addressed the CVE in version 3.8.0. See https://lists.osgeo.org/pipermail/gdal-dev/2023-November/057881.html.\n\nThe Fiona version 1.9.6 wheels on PyPI include GDAL version 3.6.4 and thus could be vulnerable. All of the Fiona 1.10 pre-release wheels in PyPI include GDAL version 3.8.4 and are not vulnerable.\n\n### Impact\nSystems which use GDAL versions prior to 3.8.0 to open unchecked zip files, whether in combination with fiona or not, could be susceptible to buffer overflows.","published":"2024-07-16T19:32:45Z","modified":"2024-12-01T05:44:08.770874Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"fiona","fixedVersion":"1.10b1"}],"fix":{"url":"https://github.com/OSGeo/gdal/commit/4aa7ca61c1d2191baf1eea2a97d0dec33a41691f","label":"OSGeo/gdal@4aa7ca6"},"references":[{"type":"WEB","url":"https://github.com/Toblerity/Fiona/security/advisories/GHSA-q5fm-55c2-v6j9"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-45853"},{"type":"WEB","url":"https://github.com/OSGeo/gdal/commit/4aa7ca61c1d2191baf1eea2a97d0dec33a41691f"},{"type":"WEB","url":"https://github.com/madler/zlib/commit/73331a6a0481067628f065ffe87bb1d8f787d10c"},{"type":"PACKAGE","url":"https://github.com/Toblerity/Fiona"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-12-01T05:44:08.770874Z"}}