huft_build in archival/libarchive/decompress_gunzip.c in BusyBox before 1.27.2 misuses a pointer, causing segfaults and an application crash during an unzip operation on a specially crafted ZIP file. http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-9261