CVE-2004-1096
EPSS 17.4%
Description
Archive::Zip Perl module before 1.14, when used by antivirus programs such as amavisd-new, allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system.
How to fix CVE-2004-1096
To remediate CVE-2004-1096, upgrade the affected package to a fixed version below.
- Debian/libarchive-zip-perl—upgrade to 1.14-1 or later
Is CVE-2004-1096 being exploited?
Moderate — EPSS is 17.4%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (1)
- from 0, < 1.14-1