Back to search
CVE-2008-0888
Published: Mar 17, 2008
Modified: Aug 26, 2025
PUBLISHED
Description
The NEEDBITS macro in the inflate_dynamic function in inflate.c for unzip can be invoked using invalid buffers, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors that trigger a free of uninitialized or previously-freed data.
| Vendor | Product | Versions |
|---|---|---|
info-zip | unzip | affected 0 - < 6.0 |
References
29415
third-party-advisory
x_refsource_SECUNIA
20080321 rPSA-2008-0116-1 unzip
mailing-list
x_refsource_BUGTRAQ
29427
third-party-advisory
x_refsource_SECUNIA
ADV-2008-1744
vdb-entry
x_refsource_VUPEN
29440
third-party-advisory
x_refsource_SECUNIA
DSA-1522
vendor-advisory
x_refsource_DEBIAN
29432
third-party-advisory
x_refsource_SECUNIA
https://issues.rpath.com/browse/RPL-2317
x_refsource_CONFIRM
http://wiki.rpath.com/Advisories:rPSA-2008-0116
x_refsource_CONFIRM
http://www.vmware.com/security/advisories/VMSA-2008-0009.html
x_refsource_CONFIRM
APPLE-SA-2010-03-29-1
vendor-advisory
x_refsource_APPLE
29392
third-party-advisory
x_refsource_SECUNIA
29681
third-party-advisory
x_refsource_SECUNIA
MDVSA-2008:068
vendor-advisory
x_refsource_MANDRIVA
SUSE-SR:2008:007
vendor-advisory
x_refsource_SUSE
ADV-2008-0913
vdb-entry
x_refsource_VUPEN
30535
third-party-advisory
x_refsource_SECUNIA
http://www.ipcop.org/index.php?name=News&file=article&sid=40
x_refsource_CONFIRM
http://support.apple.com/kb/HT4077
x_refsource_CONFIRM
GLSA-200804-06
vendor-advisory
x_refsource_GENTOO
oval:org.mitre.oval:def:9733
vdb-entry
signature
x_refsource_OVAL
29406
third-party-advisory
x_refsource_SECUNIA
29495
third-party-advisory
x_refsource_SECUNIA
31204
third-party-advisory
x_refsource_SECUNIA
1019634
vdb-entry
x_refsource_SECTRACK
RHSA-2008:0196
vendor-advisory
x_refsource_REDHAT
unzip-inflatedynamic-code-execution(41246)
vdb-entry
x_refsource_XF
USN-589-1
vendor-advisory
x_refsource_UBUNTU
28288
vdb-entry
x_refsource_BID
http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0116
x_refsource_CONFIRM
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now