CVE-2004-0994: Buffer Overflow
Multiple integer overflows in xzgv 0.8 and earlier allow remote attackers to execute arbitrary code via images with large width and height values, which trigger a heap-based buffer overflow, as demonstrated in the readprffile function in readprf.c. NOTE: CVE-2004-0994 and CVE-2004-1095 identify sets of bugs that only partially overlap, despite having the same developer. Therefore, they should be regarded as distinct.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2004-0994?
The severity of CVE-2004-0994 is typically rated as high due to the potential for remote code execution.
How do I fix CVE-2004-0994?
To fix CVE-2004-0994, upgrade to a secure version of xzgv that addresses the integer overflow vulnerabilities.
What software is affected by CVE-2004-0994?
CVE-2004-0994 affects xzgv versions 0.6, 0.7, 0.8 and zgv versions 5.5 to 5.8.
What type of vulnerability is represented by CVE-2004-0994?
CVE-2004-0994 represents an integer overflow vulnerability that can lead to a heap-based buffer overflow.
Can CVE-2004-0994 be exploited remotely?
Yes, CVE-2004-0994 can be exploited remotely through specially crafted image files with large dimensions.