CVE-2004-1095: Buffer Overflow
Multiple integer overflows in (1) readbmp.c, (2) readgif.c, (3) readgif.c, (4) readmrf.c, (5) readpcx.c, (6) readpng.c,(7) readpnm.c, (8) readprf.c, (9) readtiff.c, (10) readxbm.c, (11) readxpm.c in zgv 5.8 allow remote attackers to execute arbitrary code via certain image headers that cause calculations to be overflowed and small buffers to be allocated, leading to buffer overflows. NOTE: CVE-2004-0994 and CVE-2004-1095 identify sets of bugs that only partially overlap, despite having the same developer. Therefore, they should be regarded as distinct.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-1095?
CVE-2004-1095 has a high severity rating due to the potential for remote code execution.
How do I fix CVE-2004-1095?
To fix CVE-2004-1095, update zgv image viewer to the latest version that addresses the vulnerability.
Which versions are affected by CVE-2004-1095?
CVE-2004-1095 affects zgv versions 5.5, 5.6, 5.7, 5.8, and xzgv versions 0.6, 0.7, and 0.8.
What type of vulnerability is CVE-2004-1095?
CVE-2004-1095 is an integer overflow vulnerability that can lead to arbitrary code execution.
Is CVE-2004-1095 specific to certain operating systems?
CVE-2004-1095 primarily affects Debian GNU/Linux systems running vulnerable versions of the zgv image viewer.