CVE-2008-0888
published 2008-03-17CVE-2008-0888: The NEEDBITS macro in the inflate_dynamic function in inflate.c for unzip can be invoked using invalid buffers, which allows remote attackers to cause a denial…
PriorityP338critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
6.29%
92.8th percentile
The NEEDBITS macro in the inflate_dynamic function in inflate.c for unzip can be invoked using invalid buffers, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors that trigger a free of uninitialized or previously-freed data.
Affected
31 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | mac_os_x | < 10.6.3 | 10.6.3 |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | unzip | < unzip 5.52-11 (bookworm) | unzip 5.52-11 (bookworm) |
| info-zip | unzip | < 6.0 | 6.0 |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| msrc | unzip-6.0-16.cm1.aarch64.rpm_on_cbl_mariner_1.0_arm | — | — |
| msrc | unzip-6.0-16.cm1.x86_64.rpm_on_cbl_mariner_1.0_x64 | — | — |
| msrc | unzip-6.0-19.cm2.aarch64.rpm_on_cbl_mariner_2.0_arm | — | — |
| msrc | unzip-6.0-19.cm2.x86_64.rpm_on_cbl_mariner_2.0_x64 | — | — |
| msrc | unzip-6.0-20.azl3.aarch64.rpm_on_azure_linux_3.0_arm | — | — |
| msrc | unzip-6.0-20.azl3.x86_64.rpm_on_azure_linux_3.0_x64 | — | — |
| msrc | unzip-debuginfo-6.0-16.cm1.aarch64.rpm_on_cbl_mariner_1.0_arm | — | — |
| msrc | unzip-debuginfo-6.0-16.cm1.x86_64.rpm_on_cbl_mariner_1.0_x64 | — | — |
| msrc | unzip-debuginfo-6.0-19.cm2.aarch64.rpm_on_cbl_mariner_2.0_arm | — | — |
| msrc | unzip-debuginfo-6.0-19.cm2.x86_64.rpm_on_cbl_mariner_2.0_x64 | — | — |
| unzip_project | unzip | < 6.0 | 6.0 |
| unzip_project | unzip | >= 0 < 5.52-11 | 5.52-11 |
| unzip_project | unzip | >= 0 < 5.52-11 | 5.52-11 |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv9.3CRITICAL
vendor_redhat10.0CRITICAL
vendor_debian9.3CRITICAL
vendor_msrc9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
CVE-2008-0888: Mariner: Mariner
secalert@redhat
vendor_msrc·2024-06-11·CVSS 9.3
CVE-2008-0888 [CRITICAL] CVE-2008-0888: Mariner: Mariner
secalert@redhat
Mariner: Mariner
[email protected]: [email protected]
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade
VMware
Updates to VMware Workstation, VMware Player, VMware ACE, VMware Fusion, VMware Server, VMware VIX API, VMware ESX, VMware ESXi resolve critical security issues
vendor_vmware·2008-06-04·CVSS 2.6
CVE-2006-1721 [LOW] Updates to VMware Workstation, VMware Player, VMware ACE, VMware Fusion, VMware Server, VMware VIX API, VMware ESX, VMware ESXi resolve critical security issues
VMSA-2008-0009: Updates to VMware Workstation, VMware Player, VMware ACE, VMware Fusion, VMware Server, VMware VIX API, VMware ESX, VMware ESXi resolve critical security issues
Updates to VMware Workstation, VMware Player, VMware ACE, VMware Fusion, VMware Server, VMware VIX API, VMware ESX, VMware ESXi resolve critical security issues VMware Security Advisory VMware Security AdvisoryAdvisory ID: VMware Security AdvisorySynopsis: Updates to VMware Workstation, VMware Player, VMware ACE, VMware Fusion, VMware Server, VMware VIX API, VMware ESX, VMware ESXi resolve critical security issues VMware Security AdvisoryIssue date: VMware Security AdvisoryUpdated on:
CVEs: CVE-2006-1721, CVE-2007-4772, CVE-2007-5378, CVE-2007-5671, CVE-2008-0062, CVE-2008-0063, CVE-2008-0553, CVE-2008-0888, CVE-2
Red Hat
cups: incomplete fix for CVE-2004-0888 / CVE-2005-0206
vendor_redhat·2008-04-01·CVSS 10.0
CVE-2008-1374 [CRITICAL] cups: incomplete fix for CVE-2004-0888 / CVE-2005-0206
cups: incomplete fix for CVE-2004-0888 / CVE-2005-0206
Integer overflow in pdftops filter in CUPS in Red Hat Enterprise Linux 3 and 4, when running on 64-bit platforms, allows remote attackers to execute arbitrary code via a crafted PDF file. NOTE: this issue is due to an incomplete fix for CVE-2004-0888.
Ubuntu
unzip vulnerability
vendor_ubuntu·2008-03-20
CVE-2008-0888 unzip vulnerability
Title: unzip vulnerability
Summary: unzip vulnerability
Tavis Ormandy discovered that unzip did not correctly clean up pointers.
If a user or automated service was tricked into processing a specially
crafted ZIP archive, a remote attacker could execute arbitrary code with
user privileges.
Instructions: In general, a standard system upgrade is sufficient to effect the
necessary changes.
Red Hat
unzip: free() called for uninitialized or already freed pointer
vendor_redhat·2008-03-17·CVSS 9.3
CVE-2008-0888 [CRITICAL] unzip: free() called for uninitialized or already freed pointer
unzip: free() called for uninitialized or already freed pointer
The NEEDBITS macro in the inflate_dynamic function in inflate.c for unzip can be invoked using invalid buffers, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors that trigger a free of uninitialized or previously-freed data.
Debian
CVE-2008-0888: unzip - The NEEDBITS macro in the inflate_dynamic function in inflate.c for unzip can be...
vendor_debian·2008·CVSS 9.3
CVE-2008-0888 [CRITICAL] CVE-2008-0888: unzip - The NEEDBITS macro in the inflate_dynamic function in inflate.c for unzip can be...
The NEEDBITS macro in the inflate_dynamic function in inflate.c for unzip can be invoked using invalid buffers, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors that trigger a free of uninitialized or previously-freed data.
Scope: local
bookworm: resolved (fixed in 5.52-11)
bullseye: resolved (fixed in 5.52-11)
forky: resolved (fixed in 5.52-11)
sid: resolved (fixed in 5.52-11)
trixie: resolved (fixed in 5.52-11)
GHSA
GHSA-q7mr-xjvc-chw3: The NEEDBITS macro in the inflate_dynamic function in inflate
ghsa_unreviewed·2022-05-01
CVE-2008-0888 [HIGH] CWE-119 GHSA-q7mr-xjvc-chw3: The NEEDBITS macro in the inflate_dynamic function in inflate
The NEEDBITS macro in the inflate_dynamic function in inflate.c for unzip can be invoked using invalid buffers, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors that trigger a free of uninitialized or previously-freed data.
OSV
CVE-2008-0888: The NEEDBITS macro in the inflate_dynamic function in inflate
osv·2008-03-17·CVSS 9.3
CVE-2008-0888 [CRITICAL] CVE-2008-0888: The NEEDBITS macro in the inflate_dynamic function in inflate
The NEEDBITS macro in the inflate_dynamic function in inflate.c for unzip can be invoked using invalid buffers, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors that trigger a free of uninitialized or previously-freed data.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2008-1374 cups: incomplete fix for CVE-2004-0888 / CVE-2005-0206
bugzilla·2008-03-20·CVSS 10.0
CVE-2008-1374 [CRITICAL] CVE-2008-1374 cups: incomplete fix for CVE-2004-0888 / CVE-2005-0206
CVE-2008-1374 cups: incomplete fix for CVE-2004-0888 / CVE-2005-0206
It was discovered that patch applied to cups packages as shipped in Red Hat
Enterprise Linux 3 and 4 to address security issues in xpdf code known as
CVE-2004-0888 / CVE-2005-0206 was incomplete.
On certain platforms, malicious pdf file could still cause a crash or possibly
cause code execution when it's processed by pdftops filter.
This issue affects 64-bit platforms. cups packages in Red Hat Enterprise Linux
5 are not affected by this problem.
Discussion:
This issue was addressed in:
Red Hat Enterprise Linux:
http://rhn.redhat.com/errata/RHSA-2008-0206.html
Bugzilla
CVE-2008-0888 unzip: free() called for uninitialized or already freed pointer
bugzilla·2008-02-04·CVSS 9.3
CVE-2008-0888 [CRITICAL] CVE-2008-0888 unzip: free() called for uninitialized or already freed pointer
CVE-2008-0888 unzip: free() called for uninitialized or already freed pointer
Tavis Ormandy has discovered a flaw in unzip that can cause unzip to attempt to
free() memory block pointed to by uninitialized pointer or memory block, which
was already freed. This can cause unzip to crash (SEGV) during extraction of
malicious zip file, possibly allowing code execution.
Further details from Tavis:
the inflate_dynamic() routine (~978, inflate.c) uses a macro
NEEDBITS() that jumps execution to a cleanup routine on error, this
routine attempts to free() two buffers allocated during the inflate
process. At certain locations, the NEEDBITS() macro is used while the
pointers are not pointing to valid buffers, they are either
uninitialised or pointing inside a block that has already been free()d
(ie
http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-03/msg00008.htmlhttp://secunia.com/advisories/29392http://secunia.com/advisories/29406http://secunia.com/advisories/29415http://secunia.com/advisories/29427http://secunia.com/advisories/29432http://secunia.com/advisories/29440http://secunia.com/advisories/29495http://secunia.com/advisories/29681http://secunia.com/advisories/30535http://secunia.com/advisories/31204http://security.gentoo.org/glsa/glsa-200804-06.xmlhttp://support.apple.com/kb/HT4077http://wiki.rpath.com/Advisories:rPSA-2008-0116http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0116http://www.debian.org/security/2008/dsa-1522http://www.ipcop.org/index.php?name=News&file=article&sid=40http://www.mandriva.com/en/security/advisories?name=MDVSA-2008:068http://www.redhat.com/support/errata/RHSA-2008-0196.htmlhttp://www.securityfocus.com/archive/1/489967/100/0/threadedhttp://www.securityfocus.com/archive/1/493080/100/0/threadedhttp://www.securityfocus.com/bid/28288http://www.securitytracker.com/id?1019634http://www.ubuntu.com/usn/usn-589-1http://www.vmware.com/security/advisories/VMSA-2008-0009.htmlhttp://www.vupen.com/english/advisories/2008/0913/referenceshttp://www.vupen.com/english/advisories/2008/1744https://exchange.xforce.ibmcloud.com/vulnerabilities/41246https://issues.rpath.com/browse/RPL-2317https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9733http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-03/msg00008.htmlhttp://secunia.com/advisories/29392http://secunia.com/advisories/29406http://secunia.com/advisories/29415http://secunia.com/advisories/29427http://secunia.com/advisories/29432http://secunia.com/advisories/29440http://secunia.com/advisories/29495http://secunia.com/advisories/29681http://secunia.com/advisories/30535http://secunia.com/advisories/31204http://security.gentoo.org/glsa/glsa-200804-06.xmlhttp://support.apple.com/kb/HT4077http://wiki.rpath.com/Advisories:rPSA-2008-0116http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0116http://www.debian.org/security/2008/dsa-1522http://www.ipcop.org/index.php?name=News&file=article&sid=40http://www.mandriva.com/en/security/advisories?name=MDVSA-2008:068http://www.redhat.com/support/errata/RHSA-2008-0196.htmlhttp://www.securityfocus.com/archive/1/489967/100/0/threadedhttp://www.securityfocus.com/archive/1/493080/100/0/threadedhttp://www.securityfocus.com/bid/28288http://www.securitytracker.com/id?1019634http://www.ubuntu.com/usn/usn-589-1http://www.vmware.com/security/advisories/VMSA-2008-0009.htmlhttp://www.vupen.com/english/advisories/2008/0913/referenceshttp://www.vupen.com/english/advisories/2008/1744https://exchange.xforce.ibmcloud.com/vulnerabilities/41246https://issues.rpath.com/browse/RPL-2317https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9733
2008-03-17
Published