First published: Mon Mar 17 2008(Updated: )
The NEEDBITS macro in the inflate_dynamic function in inflate.c for unzip can be invoked using invalid buffers, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors that trigger a free of uninitialized or previously-freed data.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Info-ZIP Zip |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-0888 has a severity rating that indicates it can lead to denial of service and possible remote code execution.
To fix CVE-2008-0888, update to the latest version of Info-ZIP UnZip that addresses this vulnerability.
CVE-2008-0888 allows for denial of service attacks and potentially remote code execution by exploiting invalid buffers.
CVE-2008-0888 affects versions of Info-ZIP UnZip prior to the patch addressing the vulnerability.
Yes, CVE-2008-0888 can be exploited by remote attackers through the use of specially crafted input.