CVE Database
/

CVE-2008-0888

Back to search

CVE-2008-0888

Published: Mar 17, 2008

Modified: Aug 26, 2025

PUBLISHED

Description

The NEEDBITS macro in the inflate_dynamic function in inflate.c for unzip can be invoked using invalid buffers, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors that trigger a free of uninitialized or previously-freed data.

VendorProductVersions

info-zip

unzip

affected
0 - < 6.0

References

29415
third-party-advisory
x_refsource_SECUNIA
20080321 rPSA-2008-0116-1 unzip
mailing-list
x_refsource_BUGTRAQ
29427
third-party-advisory
x_refsource_SECUNIA
ADV-2008-1744
vdb-entry
x_refsource_VUPEN
29440
third-party-advisory
x_refsource_SECUNIA
DSA-1522
vendor-advisory
x_refsource_DEBIAN
29432
third-party-advisory
x_refsource_SECUNIA
APPLE-SA-2010-03-29-1
vendor-advisory
x_refsource_APPLE
29392
third-party-advisory
x_refsource_SECUNIA
29681
third-party-advisory
x_refsource_SECUNIA
MDVSA-2008:068
vendor-advisory
x_refsource_MANDRIVA
SUSE-SR:2008:007
vendor-advisory
x_refsource_SUSE
ADV-2008-0913
vdb-entry
x_refsource_VUPEN
30535
third-party-advisory
x_refsource_SECUNIA
GLSA-200804-06
vendor-advisory
x_refsource_GENTOO
oval:org.mitre.oval:def:9733
vdb-entry
signature
x_refsource_OVAL
29406
third-party-advisory
x_refsource_SECUNIA
29495
third-party-advisory
x_refsource_SECUNIA
31204
third-party-advisory
x_refsource_SECUNIA
1019634
vdb-entry
x_refsource_SECTRACK
RHSA-2008:0196
vendor-advisory
x_refsource_REDHAT
USN-589-1
vendor-advisory
x_refsource_UBUNTU
28288
vdb-entry
x_refsource_BID

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now