First published: Mon Mar 17 2008(Updated: )
The NEEDBITS macro in the inflate_dynamic function in inflate.c for unzip can be invoked using invalid buffers, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors that trigger a free of uninitialized or previously-freed data.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Info-ZIP UnZip |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.