The NEEDBITS macro in the inflate_dynamic function in inflate.c for unzip can be invoked using invalid buffers, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors that trigger a free of uninitialized or previously-freed data.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
History
No history.
Information
Published : 2008-03-17 21:44
Updated : 2025-05-01 15:33
NVD link : CVE-2008-0888
Mitre link : CVE-2008-0888
CVE.ORG link : CVE-2008-0888
JSON object : View
Products Affected
unzip_project
- unzip
canonical
- ubuntu_linux
debian
- debian_linux
apple
- mac_os_x
CWE
CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer
