CVE-2004-0933
high · 7.5Computer Associates (CA) InoculateIT 6.0, eTrust Antivirus r6.0 through r7.1, eTrust Antivirus for the Gateway r7.0 and r7.1, eTrust Secure Content Manager, eTrust Intrusion Detection, EZ-Armor 2.0 through 2.4, and EZ-Antivirus 6.1 through 6.3 allow remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system.
7.5
CVSS
20.7%
EPSS (exploit prob.)
97th
EPSS percentile
2005-01-27
Published
AV:N/AC:L/Au:N/C:P/I:P/A:P
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| archive_zip | archive_zip | 1.13 |
| broadcom | brightstor_arcserve_backup | 11.1 |
| broadcom | etrust_antivirus | 7.0 |
| broadcom | etrust_antivirus | 7.1 |
| broadcom | etrust_antivirus_gateway | 7.0 |
| broadcom | etrust_antivirus_gateway | 7.1 |
| broadcom | etrust_ez_antivirus | 6.1 |
| broadcom | etrust_ez_antivirus | 6.2 |
| broadcom | etrust_ez_antivirus | 6.3 |
| broadcom | etrust_ez_armor | 2.0 |
| broadcom | etrust_ez_armor | 2.3 |
| broadcom | etrust_ez_armor | 2.4 |
| broadcom | etrust_intrusion_detection | 1.4.1.13 |
| broadcom | etrust_intrusion_detection | 1.4.5 |
| broadcom | etrust_intrusion_detection | 1.5 |
| broadcom | etrust_secure_content_manager | 1.0 |
| broadcom | etrust_secure_content_manager | 1.1 |
| broadcom | inoculateit | 6.0 |
| ca | etrust_antivirus | 7.0_sp2 |
| ca | etrust_secure_content_manager | 1.0 |
| eset_software | nod32_antivirus | 1.0.11 |
| eset_software | nod32_antivirus | 1.0.12 |
| eset_software | nod32_antivirus | 1.0.13 |
| kaspersky_lab | kaspersky_anti-virus | 3.0 |
| kaspersky_lab | kaspersky_anti-virus | 4.0 |
| kaspersky_lab | kaspersky_anti-virus | 5.0 |
| mcafee | antivirus_engine | 4.3.20 |
| rav_antivirus | rav_antivirus_desktop | 8.6 |
| rav_antivirus | rav_antivirus_for_file_servers | 1.0 |
| rav_antivirus | rav_antivirus_for_mail_servers | 8.4.2 |
| sophos | sophos_anti-virus | 3.4.6 |
| sophos | sophos_anti-virus | 3.78 |
| sophos | sophos_anti-virus | 3.78d |
| sophos | sophos_anti-virus | 3.79 |
| sophos | sophos_anti-virus | 3.80 |
| sophos | sophos_anti-virus | 3.81 |
| sophos | sophos_anti-virus | 3.82 |
| sophos | sophos_anti-virus | 3.83 |
| sophos | sophos_anti-virus | 3.84 |
| sophos | sophos_anti-virus | 3.85 |
Check a specific version with /api/v1/cve/match.
References
- http://supportconnectw.ca.com/public/ca_common_docs/arclib_vuln.asp
- http://www.idefense.com/application/poi/display?id=153&type=vulnerabilities&flashstatus=true
- http://www.securityfocus.com/bid/11448
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17761
- http://supportconnectw.ca.com/public/ca_common_docs/arclib_vuln.asp
- http://www.idefense.com/application/poi/display?id=153&type=vulnerabilities&flashstatus=true
- http://www.securityfocus.com/bid/11448
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17761
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2004-0933