CVE Database
/

CVE-2004-1094

Back to search

CVE-2004-1094

Published: Dec 1, 2004

Modified: Aug 8, 2024

PUBLISHED

Description

Buffer overflow in InnerMedia DynaZip DUNZIP32.dll file version 5.00.03 and earlier allows remote attackers to execute arbitrary code via a ZIP file containing a file with a long filename, as demonstrated using (1) a .rjs (skin) file in RealPlayer 10 through RealPlayer 10.5 (6.0.12.1053), RealOne Player 1 and 2, (2) the Restore Backup function in CheckMark Software Payroll 2004/2005 3.9.6 and earlier, (3) CheckMark MultiLedger before 7.0.2, (4) dtSearch 6.x and 7.x, (5) mcupdmgr.exe and mghtml.exe in McAfee VirusScan 10 Build 10.0.21 and earlier, (6) IBM Lotus Notes before 6.5.5, and other products. NOTE: it is unclear whether this is the same vulnerability as CVE-2004-0575, although the data manipulations are the same.

VendorProductVersions

n/a

n/a

affected
n/a

References

1011944
vdb-entry
x_refsource_SECTRACK
payroll-dunzip32-bo(22737)
vdb-entry
x_refsource_XF
19906
vdb-entry
x_refsource_OSVDB
ADV-2005-2057
vdb-entry
x_refsource_VUPEN
20041027 High Risk Vulnerability in RealPlayer
mailing-list
x_refsource_BUGTRAQ
19451
third-party-advisory
x_refsource_SECUNIA
11555
vdb-entry
x_refsource_BID
17394
third-party-advisory
x_refsource_SECUNIA
realplayer-dunzip32-bo(17879)
vdb-entry
x_refsource_XF
VU#582498
third-party-advisory
x_refsource_CERT-VN
1012297
vdb-entry
x_refsource_SECTRACK
ADV-2006-1176
vdb-entry
x_refsource_VUPEN
1016817
vdb-entry
x_refsource_SECTRACK
18194
third-party-advisory
x_refsource_SECUNIA
653
third-party-advisory
x_refsource_SREASON
296
third-party-advisory
x_refsource_SREASON
17096
third-party-advisory
x_refsource_SECUNIA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now