Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2004-1096

Quick assessment

Affected
n/a n/a
Exploitation
High exploitation probability; assess promptly
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Archive::Zip是一个免费的perl模块,用于处理zip压缩文件。 Archive::Zip 1.14之前版本使用在杀毒程序中时,存在绕过安全防护漏洞。 远程攻击者可以借助一个local和global header均设为0的压缩文件,绕过杀毒程序的防护,而压缩文件本身依然可以打开。

AI Predicted 9.8 Difficulty: Trivial EPSS 17.44% · P97

Public Exploits 1

Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2004-1096

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
Archive::Zip Perl module before 1.14, when used by antivirus programs such as amavisd-new, allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Archive::Zip AntiVirus 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Archive::Zip是一个免费的perl模块,用于处理zip压缩文件。 Archive::Zip 1.14之前版本使用在杀毒程序中时,存在绕过安全防护漏洞。 远程攻击者可以借助一个local和global header均设为0的压缩文件,绕过杀毒程序的防护,而压缩文件本身依然可以打开。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
- n/a n/a -

II. Public POCs for CVE-2004-1096

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2004-1096

登录查看更多情报信息。

Vendor Advisories for CVE-2004-1096 (5)

Other References for CVE-2004-1096 (2)

Same Patch Batch · n/a · 2004-12-01 · 46 CVEs total

CVE-2004-1108 Gentoo Gentoolkit 文件覆盖漏洞
CVE-2004-1111 Cisco IOS DHCP 拒绝服务漏洞
CVE-2004-1113 SQLgreyPostfixGreylistingService email地址 SQL注入漏洞
CVE-2004-1116 mersenne.org GIMPS 本地权限提升漏洞
CVE-2004-1117 chessbrain.net ChessBrain init 用户权限提升漏洞
CVE-2004-1118 weonlydo WodFTPDLX WodFTPDLX.dll 缓冲区溢出漏洞
CVE-2004-1119 Winamp in_cdda.dll 缓冲区溢出漏洞
CVE-2004-1120 ProZilla 多个 缓冲区溢出漏洞
CVE-2004-1115 Berkeley SETI@home 本地权限提升漏洞
CVE-2004-1109 Kerio PersonalFirewall FWDRV.SYS 拒绝服务漏洞
CVE-2004-1110 MtinkStatusMonitor epso 文件覆盖漏洞
CVE-2004-1107 Gentoo Portage dispatch-conf 文件覆盖漏洞
CVE-2004-1106 Gallery index.php 跨站脚本攻击漏洞
CVE-2004-1105 Noterl ContivityVPNClient ErrorMessage 信息泄露漏洞
CVE-2004-1104 Microsoft Internet Explorer HTML格式标签URI模糊漏洞
CVE-2004-1103 Mcenter MailPost debug 信息泄露漏洞
CVE-2004-1102 Mcenter MailPost ErrorMessage 信息泄露漏洞
CVE-2004-1101 Mcenter MailPost mailpost.exe 多种安全漏洞
CVE-2004-1100 mcenter MailPost mailpost.exe 跨站脚本攻击漏洞
CVE-2004-1099 Cisco ACS 绕过身份认证漏洞

Showing top 20 of 46 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2004-1096

No comments yet


Leave a comment