The NEEDBITS macro in the inflate_dynamic function in inflate.c for unzip can be invoked using invalid buffers, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors that trigger a free of uninitialized or previously-freed data.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Unzip | — | Apply OS X security update 2010-002 | Dec 16, 2011 | Mar 17, 2008 |
| Debian | — | Upgrade unzip | Jul 30, 2024 | Mar 17, 2008 |
| Gentoo Linux | — | Upgrade app-arch/unzip. | Oct 30, 2017 | Mar 17, 2008 |
| Suse | — | Upgrade unzipUpgrade suse-release | Feb 17, 2015 | Mar 17, 2008 |
| Ubuntu | — | Upgrade unzip | Nov 8, 2024 | Mar 17, 2008 |
| Vmsa 2008 0009 | — | Apply ESX350-200805505-SG. | Nov 19, 2010 | Mar 17, 2008 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub