CVE-2004-0964: Buffer Overflow
Published Oct 20, 2004
·Updated
Buffer overflow in Zinf 2.2.1 on Windows, and other older versions for Linux, allows remote attackers or local users to execute arbitrary code via certain values in a .pls file.
Affected Software
12 affected components
Zinf Zinf=2.2.1
Debian Debian Linux=3.0
Debian Debian Linux=3.0
Debian Debian Linux=3.0
Debian Debian Linux=3.0
Debian Debian Linux=3.0
Debian Debian Linux=3.0
Debian Debian Linux=3.0
Debian Debian Linux=3.0
Debian Debian Linux=3.0
Debian Debian Linux=3.0
Debian Debian Linux=3.0
Remediation
Patch Available
Patch Available
Event History
Oct 20, 2004
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-0964?
CVE-2004-0964 is classified as a critical vulnerability due to its ability to allow remote code execution.
2
How do I fix CVE-2004-0964?
To fix CVE-2004-0964, update to a patched version of Zinf that addresses the buffer overflow issue.
3
What systems are affected by CVE-2004-0964?
CVE-2004-0964 affects Zinf version 2.2.1 on Windows and various older Linux versions of Debian 3.0.
4
Can CVE-2004-0964 be exploited remotely?
Yes, CVE-2004-0964 can be exploited remotely via specially crafted .pls files.
5
Is there a workaround for CVE-2004-0964?
A possible workaround for CVE-2004-0964 is to restrict the handling of .pls files or disable Zinf temporarily until a patch is applied.