CVE-2023-22899

Zip4j through 2.11.2, as used in Threema and other products, does not always check the MAC when decrypting a ZIP archive.
References
Link Resource
https://breakingthe3ma.app/files/Threema-PST22.pdf Exploit Technical Description Third Party Advisory
https://news.ycombinator.com/item?id=34316206 Third Party Advisory
https://github.com/srikanth-lingala/zip4j/releases Release Notes Third Party Advisory
https://breakingthe3ma.app Third Party Advisory
https://threema.ch/en/blog/posts/news-alleged-weaknesses-statement Vendor Advisory
https://github.com/srikanth-lingala/zip4j/issues/485 Exploit Issue Tracking Patch Third Party Advisory
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:zip4j_project:zip4j:*:*:*:*:*:*:*:*

Information

Published : 2023-01-09 18:15

Updated : 2023-01-30 08:24


NVD link : CVE-2023-22899

Mitre link : CVE-2023-22899


JSON object : View

CWE
CWE-346

Origin Validation Error

Advertisement

dedicated server usa

Products Affected

zip4j_project

  • zip4j