First published: Wed Dec 01 2004(Updated: )
Multiple integer overflows in (1) readbmp.c, (2) readgif.c, (3) readgif.c, (4) readmrf.c, (5) readpcx.c, (6) readpng.c,(7) readpnm.c, (8) readprf.c, (9) readtiff.c, (10) readxbm.c, (11) readxpm.c in zgv 5.8 allow remote attackers to execute arbitrary code via certain image headers that cause calculations to be overflowed and small buffers to be allocated, leading to buffer overflows. NOTE: CVE-2004-0994 and CVE-2004-1095 identify sets of bugs that only partially overlap, despite having the same developer. Therefore, they should be regarded as distinct.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
zgv | =0.8 | |
zgv | =0.6 | |
zgv image viewer | =5.5 | |
zgv image viewer | =5.8 | |
zgv image viewer | =5.7 | |
zgv | =0.7 | |
zgv image viewer | =5.6 | |
Debian Linux | =3.0 | |
Debian Linux | =3.0 | |
Debian Linux | =3.0 | |
Debian Linux | =3.0 | |
Debian Linux | =3.0 | |
Debian Linux | =3.0 | |
Debian Linux | =3.0 | |
Debian Linux | =3.0 | |
Debian Linux | =3.0 | |
Debian Linux | =3.0 | |
Debian Linux | =3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-1095 has a high severity rating due to the potential for remote code execution.
To fix CVE-2004-1095, update zgv image viewer to the latest version that addresses the vulnerability.
CVE-2004-1095 affects zgv versions 5.5, 5.6, 5.7, 5.8, and xzgv versions 0.6, 0.7, and 0.8.
CVE-2004-1095 is an integer overflow vulnerability that can lead to arbitrary code execution.
CVE-2004-1095 primarily affects Debian GNU/Linux systems running vulnerable versions of the zgv image viewer.