Back

HIGH

unzip: free() called for uninitialized or already freed pointer

Published Mar 17, 2008

Description

The NEEDBITS macro in the inflate_dynamic function in inflate.c for unzip can be invoked using invalid buffers, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors that trigger a free of uninitialized or previously-freed data.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (35)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Mar 17, 2008
Updated Aug 26, 2025
Reserved Feb 21, 2008
NVD
Status Analyzed
Modified Jun 16, 2026
Red Hat
Severity Moderate
Public date Mar 17, 2008