HIGH · 7.5

CVE-2004-1096

Archive::Zip Perl module before 1.14, when used by antivirus programs such as amavisd-new, allows remote attackers to bypass antivirus protection via a compressed file with both local and global heade...

Vulnerability Description

Archive::Zip Perl module before 1.14, when used by antivirus programs such as amavisd-new, allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system.

CVSS Score

7.5

HIGH

AV:N/AC:L/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
BroadcomBrightstor Arcserve Backup11.1
BroadcomEtrust Antivirus7.0
BroadcomEtrust Antivirus Gateway7.0
BroadcomEtrust Ez Antivirus6.1
BroadcomEtrust Ez Armor2.0
BroadcomEtrust Intrusion Detection1.4.1.13
BroadcomEtrust Secure Content Manager1.0
BroadcomInoculateit6.0
CaEtrust Antivirus7.0_sp2
CaEtrust Secure Content Manager1.0
Eset SoftwareNod32 Antivirus1.0.11
Kaspersky LabKaspersky Anti-Virus3.0
McafeeAntivirus Engine4.3.20
Rav AntivirusRav Antivirus Desktop8.6
Rav AntivirusRav Antivirus For File Servers1.0
Rav AntivirusRav Antivirus For Mail Servers8.4.2
SophosSophos Anti-Virus3.4.6
SophosSophos Puremessage Anti-Virus4.6
SophosSophos Small Business Suite1.0
GentooLinuxAll versions

References

FAQ

What is CVE-2004-1096?

CVE-2004-1096 is a vulnerability with a CVSS score of 7.5 (HIGH). Archive::Zip Perl module before 1.14, when used by antivirus programs such as amavisd-new, allows remote attackers to bypass antivirus protection via a compressed file with both local and global heade...

How severe is CVE-2004-1096?

CVE-2004-1096 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2004-1096?

Check the references section above for vendor advisories and patch information. Affected products include: Broadcom Brightstor Arcserve Backup, Broadcom Etrust Antivirus, Broadcom Etrust Antivirus Gateway, Broadcom Etrust Ez Antivirus, Broadcom Etrust Ez Armor.