CVE-2004-1096: High severity Eset Software Nod32 Antivirus vulnerability
Archive::Zip Perl module before 1.14, when used by antivirus programs such as amavisd-new, allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-1096?
CVE-2004-1096 is considered a medium severity vulnerability that allows bypassing of antivirus protection.
How do I fix CVE-2004-1096?
To fix CVE-2004-1096, upgrade the Archive::Zip Perl module to version 1.14 or later.
What systems are affected by CVE-2004-1096?
CVE-2004-1096 affects various antivirus programs using the vulnerable versions of the Archive::Zip Perl module.
What is the impact of CVE-2004-1096?
The impact of CVE-2004-1096 includes the potential for remote attackers to bypass antivirus protection and execute malicious files.
Is there a workaround for CVE-2004-1096?
A temporary workaround for CVE-2004-1096 is to restrict the use of compressed files in environments using affected antivirus products.