Wind River Support Network

HomeOther Downloadsunzip - security advisory - CVE-2008-0888
Optional Type: Patch

unzip - security advisory - CVE-2008-0888

Released: Apr 25, 2008     Updated: Apr 25, 2008

Description

The NEEDBITS macro in the inflate_dynamic function in inflate.c for unzip can be invoked using invalid buffers, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors that trigger a free of uninitialized or previously-freed data.

http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-0888 IDENTIFIER = WIND00120124


Product Version

Linux Platforms 2.0, Linux Platforms 1.x

Downloads


Installation Notes

Installation Notes

WIND00120155.zip for 2.0
WIND00122606.zip for 1.5

1. Unzip the patch under [install_dir]/updates

2. Install the patch CD by entering the patch CD directory and run setup_linux.

3. This is a source only patch so you will have to build the kernel

4. Issue a make fs and make the kernel in a configured directory.

5. Upload the kernel and rootfs into the target and boot it up.


Live chat
Online