CVE-2004-1010
zip - buffer overflow
EPSS 9.2%
Description
Buffer overflow in Info-Zip 2.3 and possibly earlier versions, when using recursive folder compression, allows remote attackers to execute arbitrary code via a ZIP file containing a long pathname.
How to fix CVE-2004-1010
To remediate CVE-2004-1010, upgrade the affected package to a fixed version below.
- Debian/zip—upgrade to 2.30-8 or later
- Debian/zip—upgrade to 2.30-5woody2 or later
Is CVE-2004-1010 being exploited?
Moderate — EPSS is 9.2%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (2)
- from 0, < 2.30-8
- from 0, < 2.30-5woody2