CVE-2004-0936

UnknownEPSS 14.79%

Last modified

CVE-2004-0936 is a vulnerability of currently unknown severity. RAV antivirus allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system.. EPSS estimates a 14.79% chance of exploitation in the next 30 days.

Description

RAV antivirus allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system.

Metrics

EPSS Probability
14.79%

96.3th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersionsUpdate
Archive ZipArchive Zip1.13
BroadcomBrightstor Arcserve Backup11.1
BroadcomEtrust Antivirus7.0
BroadcomEtrust Antivirus7.1
BroadcomEtrust Antivirus Gateway7.0
BroadcomEtrust Antivirus Gateway7.1
BroadcomEtrust Ez Antivirus6.1
BroadcomEtrust Ez Antivirus6.2
BroadcomEtrust Ez Antivirus6.3
BroadcomEtrust Ez Armor2.0
BroadcomEtrust Ez Armor2.3
BroadcomEtrust Ez Armor2.4
BroadcomEtrust Intrusion Detection1.4.1.13
BroadcomEtrust Intrusion Detection1.4.5
BroadcomEtrust Intrusion Detection1.5
BroadcomEtrust Secure Content Manager1.0
BroadcomEtrust Secure Content Manager1.1
BroadcomInoculateit6.0
CaEtrust Antivirus7.0_sp2
CaEtrust Secure Content Manager1.0Sp1
Eset SoftwareNod32 Antivirus1.0.11
Eset SoftwareNod32 Antivirus1.0.12
Eset SoftwareNod32 Antivirus1.0.13
Kaspersky LabKaspersky Anti-Virus3.0
Kaspersky LabKaspersky Anti-Virus4.0
Kaspersky LabKaspersky Anti-Virus5.0
McafeeAntivirus Engine4.3.20
Rav AntivirusRav Antivirus Desktop8.6
Rav AntivirusRav Antivirus For File Servers1.0
Rav AntivirusRav Antivirus For Mail Servers8.4.2
SophosSophos Anti-Virus3.4.6
SophosSophos Anti-Virus3.78
SophosSophos Anti-Virus3.78d
SophosSophos Anti-Virus3.79
SophosSophos Anti-Virus3.80
SophosSophos Anti-Virus3.81
SophosSophos Anti-Virus3.82
SophosSophos Anti-Virus3.83
SophosSophos Anti-Virus3.84
SophosSophos Anti-Virus3.85
SophosSophos Anti-Virus3.86
SophosSophos Puremessage Anti-Virus4.6
SophosSophos Small Business Suite1.0
GentooLinuxAll versions
GentooLinux1.4
MandrakesoftMandrake Linux10.1
SuseSuse Linux9.2

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2004-0936?
RAV antivirus allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system.
How severe is CVE-2004-0936?
Severity scoring for CVE-2004-0936 is pending analysis. The EPSS model estimates a 14.79% probability of exploitation in the next 30 days.
How do I fix CVE-2004-0936?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2004-0936?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST