Vulnerability Name:

CVE-2004-0994 (CCN-18454)

Assigned:2004-12-13
Published:2004-12-13
Updated:2017-07-11
Summary:Multiple integer overflows in xzgv 0.8 and earlier allow remote attackers to execute arbitrary code via images with large width and height values, which trigger a heap-based buffer overflow, as demonstrated in the read_prf_file function in readprf.c.
Note: CVE-2004-0994 and CVE-2004-1095 identify sets of bugs that only partially overlap, despite having the same developer. Therefore, they should be regarded as distinct.
CVSS v3 Severity:10.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
10.0 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Type:CWE-Other
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2004-0994

Source: IDEFENSE
Type: UNKNOWN
20041213 Multiple Vendor xzgv PRF Parsing Integer Overflow Vulnerability

Source: CONFIRM
Type: UNKNOWN
http://rus.members.beeb.net/xzgv-0.8-integer-overflow-fix.diff

Source: CCN
Type: xzgv Web page
xzgv

Source: DEBIAN
Type: UNKNOWN
DSA-614

Source: DEBIAN
Type: DSA-614
xzgv -- integer overflows

Source: CCN
Type: GLSA-200501-09
xzgv: Multiple overflows

Source: CCN
Type: iDEFENSE Security Advisory 12.13.04
Multiple Vendor xzgv PRF Parsing Integer Overflow Vulnerability

Source: CCN
Type: OSVDB ID: 12357
xzgv read_prf_file Method Remote Overflow

Source: XF
Type: UNKNOWN
xzgv-readprffile-bo(18454)

Source: XF
Type: UNKNOWN
xzgv-readprffile-bo(18454)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:zgv:xzgv_image_viewer:0.6:*:*:*:*:*:*:*
  • OR cpe:/a:zgv:xzgv_image_viewer:0.7:*:*:*:*:*:*:*
  • OR cpe:/a:zgv:xzgv_image_viewer:0.8:*:*:*:*:*:*:*
  • OR cpe:/a:zgv:zgv_image_viewer:5.5:*:*:*:*:*:*:*
  • OR cpe:/a:zgv:zgv_image_viewer:5.6:*:*:*:*:*:*:*
  • OR cpe:/a:zgv:zgv_image_viewer:5.7:*:*:*:*:*:*:*
  • OR cpe:/a:zgv:zgv_image_viewer:5.8:*:*:*:*:*:*:*

  • Configuration 2:
  • cpe:/o:debian:debian_linux:3.0:*:alpha:*:*:*:*:*
  • OR cpe:/o:debian:debian_linux:3.0:*:arm:*:*:*:*:*
  • OR cpe:/o:debian:debian_linux:3.0:*:hppa:*:*:*:*:*
  • OR cpe:/o:debian:debian_linux:3.0:*:ia-32:*:*:*:*:*
  • OR cpe:/o:debian:debian_linux:3.0:*:ia-64:*:*:*:*:*
  • OR cpe:/o:debian:debian_linux:3.0:*:m68k:*:*:*:*:*
  • OR cpe:/o:debian:debian_linux:3.0:*:mips:*:*:*:*:*
  • OR cpe:/o:debian:debian_linux:3.0:*:mipsel:*:*:*:*:*
  • OR cpe:/o:debian:debian_linux:3.0:*:ppc:*:*:*:*:*
  • OR cpe:/o:debian:debian_linux:3.0:*:s-390:*:*:*:*:*
  • OR cpe:/o:debian:debian_linux:3.0:*:sparc:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:xzgv:xzgv:0.8:*:*:*:*:*:*:*
  • AND
  • cpe:/o:freebsd:freebsd:*:*:*:*:*:*:*:*
  • OR cpe:/o:debian:debian_linux:*:*:*:*:*:*:*:*
  • OR cpe:/o:suse:suse_linux:*:*:*:*:*:*:*:*
  • OR cpe:/o:debian:debian_linux:3.0:*:*:*:*:*:*:*
  • OR cpe:/o:gentoo:linux:*:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.debian:def:614
    V
    integer overflows
    2004-12-21
    BACK
    zgv xzgv image viewer 0.6
    zgv xzgv image viewer 0.7
    zgv xzgv image viewer 0.8
    zgv zgv image viewer 5.5
    zgv zgv image viewer 5.6
    zgv zgv image viewer 5.7
    zgv zgv image viewer 5.8
    debian debian linux 3.0
    debian debian linux 3.0
    debian debian linux 3.0
    debian debian linux 3.0
    debian debian linux 3.0
    debian debian linux 3.0
    debian debian linux 3.0
    debian debian linux 3.0
    debian debian linux 3.0
    debian debian linux 3.0
    debian debian linux 3.0
    xzgv xzgv 0.8
    freebsd freebsd *
    debian debian linux *
    suse suse linux *
    debian debian linux 3.0
    gentoo linux *