CVE-2008-0888
17.03.2008, 21:44
The NEEDBITS macro in the inflate_dynamic function in inflate.c for unzip can be invoked using invalid buffers, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors that trigger a free of uninitialized or previously-freed data.Enginsight
| Vendor | Product | Version |
|---|---|---|
| canonical | ubuntu_linux | 6.06 |
| canonical | ubuntu_linux | 6.10 |
| canonical | ubuntu_linux | 7.04 |
| canonical | ubuntu_linux | 7.10 |
| apple | mac_os_x | 𝑥 < 10.6.3 |
| debian | debian_linux | 4.0 |
| unzip_project | unzip | 𝑥 < 6.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Common Weakness Enumeration
References