CVE-2004-0933
Last modified
CVE-2004-0933 is a vulnerability of currently unknown severity. Computer Associates (CA) InoculateIT 6.0, eTrust Antivirus r6.0 through r7.1, eTrust Antivirus for the Gateway r7.0 and r7.1, eTrust Secure Content Manager, eTrust Intrusion Detection, EZ-Armor 2.0 through 2.4, and EZ-Antivirus 6.1 through 6.3 allow remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system.. EPSS estimates a 20.69% chance of exploitation in the next 30 days.
Description
Computer Associates (CA) InoculateIT 6.0, eTrust Antivirus r6.0 through r7.1, eTrust Antivirus for the Gateway r7.0 and r7.1, eTrust Secure Content Manager, eTrust Intrusion Detection, EZ-Armor 2.0 through 2.4, and EZ-Antivirus 6.1 through 6.3 allow remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system.
Metrics
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Archive Zip | Archive Zip | 1.13 | — |
| Broadcom | Brightstor Arcserve Backup | 11.1 | — |
| Broadcom | Etrust Antivirus | 7.0 | — |
| Broadcom | Etrust Antivirus | 7.1 | — |
| Broadcom | Etrust Antivirus Gateway | 7.0 | — |
| Broadcom | Etrust Antivirus Gateway | 7.1 | — |
| Broadcom | Etrust Ez Antivirus | 6.1 | — |
| Broadcom | Etrust Ez Antivirus | 6.2 | — |
| Broadcom | Etrust Ez Antivirus | 6.3 | — |
| Broadcom | Etrust Ez Armor | 2.0 | — |
| Broadcom | Etrust Ez Armor | 2.3 | — |
| Broadcom | Etrust Ez Armor | 2.4 | — |
| Broadcom | Etrust Intrusion Detection | 1.4.1.13 | — |
| Broadcom | Etrust Intrusion Detection | 1.4.5 | — |
| Broadcom | Etrust Intrusion Detection | 1.5 | — |
| Broadcom | Etrust Secure Content Manager | 1.0 | — |
| Broadcom | Etrust Secure Content Manager | 1.1 | — |
| Broadcom | Inoculateit | 6.0 | — |
| Ca | Etrust Antivirus | 7.0_sp2 | — |
| Ca | Etrust Secure Content Manager | 1.0 | Sp1 |
| Eset Software | Nod32 Antivirus | 1.0.11 | — |
| Eset Software | Nod32 Antivirus | 1.0.12 | — |
| Eset Software | Nod32 Antivirus | 1.0.13 | — |
| Kaspersky Lab | Kaspersky Anti-Virus | 3.0 | — |
| Kaspersky Lab | Kaspersky Anti-Virus | 4.0 | — |
| Kaspersky Lab | Kaspersky Anti-Virus | 5.0 | — |
| Mcafee | Antivirus Engine | 4.3.20 | — |
| Rav Antivirus | Rav Antivirus Desktop | 8.6 | — |
| Rav Antivirus | Rav Antivirus For File Servers | 1.0 | — |
| Rav Antivirus | Rav Antivirus For Mail Servers | 8.4.2 | — |
| Sophos | Sophos Anti-Virus | 3.4.6 | — |
| Sophos | Sophos Anti-Virus | 3.78 | — |
| Sophos | Sophos Anti-Virus | 3.78d | — |
| Sophos | Sophos Anti-Virus | 3.79 | — |
| Sophos | Sophos Anti-Virus | 3.80 | — |
| Sophos | Sophos Anti-Virus | 3.81 | — |
| Sophos | Sophos Anti-Virus | 3.82 | — |
| Sophos | Sophos Anti-Virus | 3.83 | — |
| Sophos | Sophos Anti-Virus | 3.84 | — |
| Sophos | Sophos Anti-Virus | 3.85 | — |
| Sophos | Sophos Anti-Virus | 3.86 | — |
| Sophos | Sophos Puremessage Anti-Virus | 4.6 | — |
| Sophos | Sophos Small Business Suite | 1.0 | — |
| Gentoo | Linux | All versions | — |
| Gentoo | Linux | 1.4 | — |
| Mandrakesoft | Mandrake Linux | 10.1 | — |
| Suse | Suse Linux | 9.2 | — |
References
- http://www.securityfocus.com/bid/11448Exploit, Patch, Vendor Advisory
- http://www.securityfocus.com/bid/11448Exploit, Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2004-0933?
How severe is CVE-2004-0933?
How do I fix CVE-2004-0933?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2004
- CVE-2004-0927ServerAdmin in Mac OS X 10.2.8 through 10.3.5 uses the same …
- CVE-2004-0928The Microsoft IIS Connector in JRun 4.0 and Macromedia ColdF…
- CVE-2004-0929Heap-based buffer overflow in the OJPEGVSetField function in…
- CVE-2004-0930The ms_fnmatch function in Samba 3.0.4 and 3.0.7 and possibl…
- CVE-2004-0931MySQL MaxDB before 7.5.00.18 allows remote attackers to caus…
- CVE-2004-0932McAfee Anti-Virus Engine DATS drivers before 4398 released o…
- CVE-2004-0934Kaspersky 3.x to 4.x allows remote attackers to bypass antiv…
- CVE-2004-0935Eset Anti-Virus before 1.020 (16th September 2004) allows re…
- CVE-2004-0936RAV antivirus allows remote attackers to bypass antivirus pr…
- CVE-2004-0937Sophos Anti-Virus before 3.87.0, and Sophos Anti-Virus for W…
- CVE-2004-0938FreeRADIUS before 1.0.1 allows remote attackers to cause a d…
- CVE-2004-0939changepassword.cgi in Neoteris Instant Virtual Extranet (IVE…
Are you affected by CVE-2004-0933?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
