The NEEDBITS macro in the inflate_dynamic function in inflate.c for unzip can be invoked using invalid buffers, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors that trigger a free of uninitialized or previously-freed data.
References
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: redhat
Published: 2008-03-17T21:00:00
Updated: 2018-10-15T20:57:01
Reserved: 2008-02-21T00:00:00
Link: CVE-2008-0888
JSON object: View
NVD Information
Status : Modified
Published: 2008-03-17T21:44:00.000
Modified: 2018-10-15T22:03:22.697
Link: CVE-2008-0888
JSON object: View
Redhat Information
No data.
CWE