InnerMedia DynaZip Remote Stack Based Buffer Overflow Vulnerability

BID:11555

Info

InnerMedia DynaZip Remote Stack Based Buffer Overflow Vulnerability

Bugtraq ID: 11555
Class: Boundary Condition Error
CVE: CVE-2004-1094
Remote: Yes
Local: No
Published: Oct 27 2004 12:00AM
Updated: Mar 19 2015 09:13AM
Credit: Discovery of this vulnerability is credited to Yuji Ukai of eEye Digital Security and John Heasman of NGSSoftware. Juha-Matti Laurio of Networksecurity.fi discovered this issue in CheckMark Payroll and IBM Lotus Notes.
Vulnerable: Real Networks RealPlayer 10.5 v6.0.12.1056
Real Networks RealPlayer 10.5 v6.0.12.1053
Real Networks RealPlayer 10.5 v6.0.12.1040
Real Networks RealPlayer 10.5 Beta v6.0.12.1016
Real Networks RealPlayer 10.5
Real Networks RealPlayer 10.0 BETA
Real Networks RealPlayer 10.0 v6.0.12.690
Real Networks RealPlayer 10.0
+ S.u.S.E. cvsup-16.1h-43.i586.rpm
+ S.u.S.E. Linux Personal 9.3
+ S.u.S.E. Linux Personal 9.2
Real Networks RealOne Player 2.0
Real Networks RealOne Player 1.0
McAfee VirusScan 10.0.21
McAfee SecurityCenter Agent 6.0 .16
InnerMedia DynaZip Library 3.0 .0.14
InnerMedia DynaZip Library 5.00.03
InnerMedia DynaZip Library 5.00.02
InnerMedia DynaZip Library 5.00.01
InnerMedia DynaZip Library 5.00.00
IBM Lotus Notes 6.5.4
IBM Lotus Notes 6.5.3
IBM Lotus Notes 6.5.2
IBM Lotus Notes 6.5.1
IBM Lotus Notes 6.5
dtSearch Corp dtSearch with Spider 7.10 Build 7045
dtSearch Corp dtSearch with Spider
dtSearch Corp dtSearch 6.5 Build 6608
dtSearch Corp dtSearch 5.25
CheckMark Software Inc. MultiLedger 7.0
CheckMark Software Inc. MultiLedger 6.0.3
CheckMark Software Inc. CheckMark Payroll 3.9.6
CheckMark Software Inc. CheckMark Payroll 3.9.5
CheckMark Software Inc. CheckMark Payroll 3.9.4
CheckMark Software Inc. CheckMark Payroll 3.9.3
CheckMark Software Inc. CheckMark Payroll 3.9.2
CheckMark Software Inc. CheckMark Payroll 3.9.1
Not Vulnerable: Real Networks RealPlayer 10.5 v6.0.12.1056
InnerMedia DynaZip Library 5.00.04
IBM Lotus Notes 6.5.5
IBM Lotus Notes 7.0
dtSearch Corp dtSearch with Spider 7.20 Build 7136
CheckMark Software Inc. MultiLedger 7.0.2
CheckMark Software Inc. CheckMark Payroll 3.9.7

Discussion

InnerMedia DynaZip Remote Stack Based Buffer Overflow Vulnerability

DynaZip is susceptible to a stack-based buffer-overflow vulnerability. This issue is due to the library's failure to properly bounds-check user-supplied data before copying it to an insufficiently sized memory buffer.

A remote attacker may exploit this vulnerability to execute arbitrary instructions in the context of an application that uses the affected library.

The following applications are known to include vulnerable versions of the affected library:

- RealPlayer for Microsoft Windows
- RealOne Player for Microsoft Windows
- CheckMark Payroll 2004/2005.

Other applications also likely include the vulnerable library.

Exploit / POC

InnerMedia DynaZip Remote Stack Based Buffer Overflow Vulnerability

The discoverer of this vulnerability has developed an exploit, which is not believed to be in public circulation.

Solution / Fix

InnerMedia DynaZip Remote Stack Based Buffer Overflow Vulnerability

Solution:
Please see the references for more information and fixes by vendors.


CheckMark Software Inc. CheckMark Payroll 3.9.1

CheckMark Software Inc. CheckMark Payroll 3.9.2

CheckMark Software Inc. CheckMark Payroll 3.9.3

CheckMark Software Inc. CheckMark Payroll 3.9.4

CheckMark Software Inc. CheckMark Payroll 3.9.5

CheckMark Software Inc. CheckMark Payroll 3.9.6

CheckMark Software Inc. MultiLedger 7.0

References

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report