CVE-2004-2713: Low severity Zonelabs ZoneAlarm vulnerability
DISPUTED Zone Alarm Pro 1.0 through 5.1 gives full access to %windir%\Internet Logs\ to the EVERYONE group, which allows local users to cause a denial of service by modifying the folder contents or permissions. NOTE: this issue has been disputed by the vendor, who claims that it does not affect product functionality since the same information is also saved in a protected file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2004-2713?
CVE-2004-2713 is considered a low severity vulnerability since it primarily allows local users to modify folder contents.
How do I fix CVE-2004-2713?
To fix CVE-2004-2713, restrict access permissions to the %windir%\Internet Logs\ folder for the EVERYONE group.
Which software is affected by CVE-2004-2713?
CVE-2004-2713 affects Zone Alarm Pro versions 1.0 through 5.1.
What type of attack does CVE-2004-2713 enable?
CVE-2004-2713 enables local users to perform a denial of service attack by modifying files within the Internet Logs directory.
Is the vulnerability CVE-2004-2713 confirmed or disputed?
CVE-2004-2713 is disputed by the vendor, who claims that the issue does not affect their software.