CVE-2004-0994

Multiple integer overflows in xzgv 0.8 and earlier allow remote attackers to execute arbitrary code via images with large width and height values, which trigger a heap-based buffer overflow, as demonstrated in the read_prf_file function in readprf.c. NOTE: CVE-2004-0994 and CVE-2004-1095 identify sets of bugs that only partially overlap, despite having the same developer. Therefore, they should be regarded as distinct.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:zgv:xzgv_image_viewer:0.6:*:*:*:*:*:*:*
cpe:2.3:a:zgv:xzgv_image_viewer:0.7:*:*:*:*:*:*:*
cpe:2.3:a:zgv:xzgv_image_viewer:0.8:*:*:*:*:*:*:*
cpe:2.3:a:zgv:zgv_image_viewer:5.5:*:*:*:*:*:*:*
cpe:2.3:a:zgv:zgv_image_viewer:5.6:*:*:*:*:*:*:*
cpe:2.3:a:zgv:zgv_image_viewer:5.7:*:*:*:*:*:*:*
cpe:2.3:a:zgv:zgv_image_viewer:5.8:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:debian:debian_linux:3.0:*:alpha:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:3.0:*:arm:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:3.0:*:hppa:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:3.0:*:ia-32:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:3.0:*:ia-64:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:3.0:*:m68k:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:3.0:*:mips:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:3.0:*:mipsel:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:3.0:*:ppc:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:3.0:*:s-390:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:3.0:*:sparc:*:*:*:*:*

History

20 Nov 2024, 23:49

Type Values Removed Values Added
References () http://marc.info/?l=bugtraq&m=110297198402077&w=2 - () http://marc.info/?l=bugtraq&m=110297198402077&w=2 -
References () http://rus.members.beeb.net/xzgv-0.8-integer-overflow-fix.diff - () http://rus.members.beeb.net/xzgv-0.8-integer-overflow-fix.diff -
References () http://www.debian.org/security/2004/dsa-614 - () http://www.debian.org/security/2004/dsa-614 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/18454 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/18454 -

Information

Published : 2005-01-10 05:00

Updated : 2024-11-20 23:49


NVD link : CVE-2004-0994

Mitre link : CVE-2004-0994

CVE.ORG link : CVE-2004-0994


JSON object : View

Products Affected

debian

  • debian_linux

zgv

  • xzgv_image_viewer
  • zgv_image_viewer