CVE-2004-1095
Summary
| CVE | CVE-2004-1095 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2005-01-10 05:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | Multiple integer overflows in (1) readbmp.c, (2) readgif.c, (3) readgif.c, (4) readmrf.c, (5) readpcx.c, (6) readpng.c,(7) readpnm.c, (8) readprf.c, (9) readtiff.c, (10) readxbm.c, (11) readxpm.c in zgv 5.8 allow remote attackers to execute arbitrary code via certain image headers that cause calculations to be overflowed and small buffers to be allocated, leading to buffer overflows. NOTE: CVE-2004-0994 and CVE-2004-1095 identify sets of bugs that only partially overlap, despite having the same developer. Therefore, they should be regarded as distinct. |
Risk And Classification
Primary CVSS: v2.0 10 from [email protected]
AV:N/AC:L/Au:N/C:C/I:C/A:C
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Debian | Debian Linux | 3.0 | All | alpha | All |
| Operating System | Debian | Debian Linux | 3.0 | All | arm | All |
| Operating System | Debian | Debian Linux | 3.0 | All | hppa | All |
| Operating System | Debian | Debian Linux | 3.0 | All | ia-32 | All |
| Operating System | Debian | Debian Linux | 3.0 | All | ia-64 | All |
| Operating System | Debian | Debian Linux | 3.0 | All | m68k | All |
| Operating System | Debian | Debian Linux | 3.0 | All | mips | All |
| Operating System | Debian | Debian Linux | 3.0 | All | mipsel | All |
| Operating System | Debian | Debian Linux | 3.0 | All | ppc | All |
| Operating System | Debian | Debian Linux | 3.0 | All | s-390 | All |
| Operating System | Debian | Debian Linux | 3.0 | All | sparc | All |
| Application | Zgv | Xzgv Image Viewer | 0.6 | All | All | All |
| Application | Zgv | Xzgv Image Viewer | 0.7 | All | All | All |
| Application | Zgv | Xzgv Image Viewer | 0.8 | All | All | All |
| Application | Zgv | Zgv Image Viewer | 5.5 | All | All | All |
| Application | Zgv | Zgv Image Viewer | 5.6 | All | All | All |
| Application | Zgv | Zgv Image Viewer | 5.7 | All | All | All |
| Application | Zgv | Zgv Image Viewer | 5.8 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 'Re: zgv image viewing heap overflows' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| www.svgalib.org/rus/zgv/zgv-5.8-integer-overflow-fix.diff | af854a3a-2127-422b-91ae-364da2661108 | www.svgalib.org | |
| Gentoo Linux Documentation -- zgv: Multiple buffer overflows | af854a3a-2127-422b-91ae-364da2661108 | www.gentoo.org | |
| ZGV And XZGV Image Viewer Multiple Remote Integer Overflow Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Patch, Vendor Advisory |
| 'zgv image viewing heap overflows' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| www.svgalib.org/rus/zgv | af854a3a-2127-422b-91ae-364da2661108 | www.svgalib.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.