Return to CVE list

CVE-2008-0888

9.3
Critical

CVE-2008-0888

secalert@redhat.com
Modified

Description

The NEEDBITS macro in the inflate_dynamic function in inflate.c for unzip can be invoked using invalid buffers, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors that trigger a free of uninitialized or previously-freed data.

Exploits

No known exploits found for this CVE.

Search Exploit-DB

References

af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/29392
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/29406
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/29415
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/29427
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/29432
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/29440
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/29495
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/29681
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/30535
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/31204
af854a3a-2127-422b-91ae-364da2661108
http://security.gentoo.org/glsa/glsa-200804-06.xml
af854a3a-2127-422b-91ae-364da2661108
http://support.apple.com/kb/HT4077
af854a3a-2127-422b-91ae-364da2661108
http://wiki.rpath.com/Advisories:rPSA-2008-0116
af854a3a-2127-422b-91ae-364da2661108
http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0116
af854a3a-2127-422b-91ae-364da2661108
http://www.debian.org/security/2008/dsa-1522
af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/bid/28288
af854a3a-2127-422b-91ae-364da2661108
http://www.securitytracker.com/id?1019634
af854a3a-2127-422b-91ae-364da2661108
http://www.ubuntu.com/usn/usn-589-1
af854a3a-2127-422b-91ae-364da2661108
http://www.vupen.com/english/advisories/2008/1744
af854a3a-2127-422b-91ae-364da2661108
https://issues.rpath.com/browse/RPL-2317