CVE-2008-0888: Buffer Overflow
The NEEDBITS macro in the inflatedynamic function in inflate.c for unzip can be invoked using invalid buffers, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors that trigger a free of uninitialized or previously-freed data.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2008-0888?
CVE-2008-0888 has a severity rating that indicates it can lead to denial of service and possible remote code execution.
How do I fix CVE-2008-0888?
To fix CVE-2008-0888, update to the latest version of Info-ZIP UnZip that addresses this vulnerability.
What type of attack does CVE-2008-0888 facilitate?
CVE-2008-0888 allows for denial of service attacks and potentially remote code execution by exploiting invalid buffers.
Which software is affected by CVE-2008-0888?
CVE-2008-0888 affects versions of Info-ZIP UnZip prior to the patch addressing the vulnerability.
Can CVE-2008-0888 be exploited remotely?
Yes, CVE-2008-0888 can be exploited by remote attackers through the use of specially crafted input.