CVE-2023-22899

Zip4j through 2.11.2, as used in Threema and other products, does not always check the MAC when decrypting a ZIP archive.
References
Link Resource
https://breakingthe3ma.app Third Party Advisory
https://breakingthe3ma.app/files/Threema-PST22.pdf Exploit Technical Description Third Party Advisory
https://github.com/srikanth-lingala/zip4j/issues/485 Exploit Issue Tracking Patch Third Party Advisory
https://github.com/srikanth-lingala/zip4j/releases Release Notes Third Party Advisory
https://news.ycombinator.com/item?id=34316206 Third Party Advisory
https://threema.ch/en/blog/posts/news-alleged-weaknesses-statement Vendor Advisory
https://breakingthe3ma.app Third Party Advisory
https://breakingthe3ma.app/files/Threema-PST22.pdf Exploit Technical Description Third Party Advisory
https://github.com/srikanth-lingala/zip4j/issues/485 Exploit Issue Tracking Patch Third Party Advisory
https://github.com/srikanth-lingala/zip4j/releases Release Notes Third Party Advisory
https://news.ycombinator.com/item?id=34316206 Third Party Advisory
https://threema.ch/en/blog/posts/news-alleged-weaknesses-statement Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:zip4j_project:zip4j:*:*:*:*:*:*:*:*

History

21 Nov 2024, 07:45

Type Values Removed Values Added
Summary
  • (es) Zip4j hasta 2.11.2, como se usa en Threema y otros productos, no siempre verifica la MAC al descifrar un archivo ZIP.
References () https://breakingthe3ma.app - Third Party Advisory () https://breakingthe3ma.app - Third Party Advisory
References () https://breakingthe3ma.app/files/Threema-PST22.pdf - Exploit, Technical Description, Third Party Advisory () https://breakingthe3ma.app/files/Threema-PST22.pdf - Exploit, Technical Description, Third Party Advisory
References () https://github.com/srikanth-lingala/zip4j/issues/485 - Exploit, Issue Tracking, Patch, Third Party Advisory () https://github.com/srikanth-lingala/zip4j/issues/485 - Exploit, Issue Tracking, Patch, Third Party Advisory
References () https://github.com/srikanth-lingala/zip4j/releases - Release Notes, Third Party Advisory () https://github.com/srikanth-lingala/zip4j/releases - Release Notes, Third Party Advisory
References () https://news.ycombinator.com/item?id=34316206 - Third Party Advisory () https://news.ycombinator.com/item?id=34316206 - Third Party Advisory
References () https://threema.ch/en/blog/posts/news-alleged-weaknesses-statement - Vendor Advisory () https://threema.ch/en/blog/posts/news-alleged-weaknesses-statement - Vendor Advisory

Information

Published : 2023-01-10 02:15

Updated : 2024-11-21 07:45


NVD link : CVE-2023-22899

Mitre link : CVE-2023-22899

CVE.ORG link : CVE-2023-22899


JSON object : View

Products Affected

zip4j_project

  • zip4j
CWE
CWE-346

Origin Validation Error