Upstream information
Description
The NEEDBITS macro in the inflate_dynamic function in inflate.c for unzip can be invoked using invalid buffers, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors that trigger a free of uninitialized or previously-freed data.NVD CVSS v2 Base Score: 9.3 (AV:N/AC:M/Au:N/C:C/I:C/A:C)
Novell/SUSE information
Novell Bugzilla entry: 358425 SUSE Security Advisories:- SUSE-SR:2008:007, published Fri, 28 Mar 2008 15:00:00 +0000
List of released packages
| Product(s) | Fixed package version(s) | References |
|---|---|---|
| SUSE Linux Enterprise Desktop 10 SP1 for AMD64 and Intel EM64T SUSE Linux Enterprise Desktop 10 SP1 for x86 SUSE Linux Enterprise Server 10 SP1 for AMD64 and Intel EM64T SUSE Linux Enterprise Server 10 SP1 for IBM POWER SUSE Linux Enterprise Server 10 SP1 for IBM zSeries 64bit SUSE Linux Enterprise Server 10 SP1 for IPF SUSE Linux Enterprise Server 10 SP1 for x86 |
| sled10.x86 sles10.s390x ZYPP Patch Nr: 4977 |
| SUSE LINUX 10.1 |
| |
| openSUSE 10.2 |
| |
| openSUSE 10.3 |
|
