CVE-2004-1096 - CVE House
Back to Database
Status published High CVE-2004-1096

Archive::Zip Perl module before 1.14, when used by antivirus programs...

Vulnerability Description

Archive::Zip Perl module before 1.14, when used by antivirus programs such as amavisd-new, allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2004-1096

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

brightstor arcserve backup, etrust antivirus, etrust antivirus gateway, etrust ez antivirus, etrust ez armor, etrust intrusion detection, etrust secure content manager, inoculateit, nod32 antivirus, kaspersky anti-virus, antivirus engine, rav antivirus desktop, rav antivirus for file servers, rav antivirus for mail servers, sophos anti-virus, sophos puremessage anti-virus, sophos small business suite, linux, mandrake linux, suse linux
Vulnerable Versions:
11.1, 7.0, 7.1, 6.1, 6.2, 6.3, 2.0, 2.3, 2.4, 1.4.1.13, 1.4.5, 1.5, 1.0, 1.1, 6.0, 7.0_sp2, 1.0.11, 1.0.12, 1.0.13, 3.0, 4.0, 5.0, 4.3.20, 8.6, 8.4.2, 3.4.6, 3.78, 3.78d, 3.79, 3.80, 3.81, 3.82, 3.83, 3.84, 3.85, 3.86, 4.6, 1.4, 10.1, 9.2

Timeline

Official Publish: December 1st, 2004
Last Modified: August 8th, 2024
Added to House: July 18th, 2026

CVSS Vectors

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.