First published: Fri Nov 19 2004(Updated: )
Kaspersky 3.x to 4.x allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Perl Archive::Zip | =1.13 | |
Broadcom ARCserve Backup | =11.1 | |
Broadcom eTrust Antivirus | =7.0 | |
Broadcom eTrust Antivirus | =7.1 | |
CA eTrust Anti-Virus Gateway | =7.0 | |
CA eTrust Anti-Virus Gateway | =7.1 | |
Broadcom eTrust EZ Antivirus | =6.1 | |
Broadcom eTrust EZ Antivirus | =6.2 | |
Broadcom eTrust EZ Antivirus | =6.3 | |
Broadcom eTrust EZ Armor | =2.0 | |
Broadcom eTrust EZ Armor | =2.3 | |
Broadcom eTrust EZ Armor | =2.4 | |
Broadcom eTrust Intrusion Detection | =1.4.1.13 | |
Broadcom eTrust Intrusion Detection | =1.4.5 | |
Broadcom eTrust Intrusion Detection | =1.5 | |
Broadcom Secure Content Manager | =1.0 | |
Broadcom Secure Content Manager | =1.1 | |
Broadcom InoculateIT | =6.0 | |
Broadcom eTrust Antivirus | =7.0_sp2 | |
Broadcom Secure Content Manager | =1.0-sp1 | |
ESET NOD32 Antivirus | =1.0.11 | |
ESET NOD32 Antivirus | =1.0.12 | |
ESET NOD32 Antivirus | =1.0.13 | |
Kaspersky Anti-Virus | =3.0 | |
Kaspersky Anti-Virus | =4.0 | |
Kaspersky Anti-Virus | =5.0 | |
McAfee Antivirus Engine | =4.3.20 | |
RAV Antivirus Desktop | =8.6 | |
rav Antivirus for file servers | =1.0 | |
rav Antivirus for mail servers | =8.4.2 | |
Sophos Anti-Virus | =3.4.6 | |
Sophos Anti-Virus | =3.78 | |
Sophos Anti-Virus | =3.78d | |
Sophos Anti-Virus | =3.79 | |
Sophos Anti-Virus | =3.80 | |
Sophos Anti-Virus | =3.81 | |
Sophos Anti-Virus | =3.82 | |
Sophos Anti-Virus | =3.83 | |
Sophos Anti-Virus | =3.84 | |
Sophos Anti-Virus | =3.85 | |
Sophos Anti-Virus | =3.86 | |
Sophos PureMessage Anti-virus | =4.6 | |
Sophos Small Business Suite | =1.0 | |
Gentoo Linux | ||
Gentoo Linux | =1.4 | |
Mandrake Linux | =10.1 | |
Mandrake Linux | =10.1 | |
SUSE Linux | =9.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-0934 is classified as a medium severity vulnerability due to its potential to bypass antivirus protections.
To mitigate CVE-2004-0934, it's recommended to upgrade to the latest version of the affected antivirus software that provides patches against this vulnerability.
CVE-2004-0934 affects Kaspersky Anti-Virus versions 3.x to 4.x, along with other antivirus software listed in the vulnerability details.
CVE-2004-0934 allows remote attackers to bypass antivirus protection through a specific method involving compressed files.
Yes, there are known exploitation methods for CVE-2004-0934 that leverage the vulnerability's characteristics to evade detection by antivirus software.