CVE-2004-1096

Archive::Zip <1.14 - Open Redirect

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2004-1096.

AI-analyzed exploit summary This PoC exploits multiple ZIP file parsing vulnerabilities (CAN-2004-0932 to CAN-2004-0937) by patching specific offsets in local and central headers to trigger flaws in various antivirus engines. It modifies ZIP files to create malformed headers that could bypass or crash affected software.

Description

Archive::Zip Perl module before 1.14, when used by antivirus programs such as amavisd-new, allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system.

Exploits (1)

exploitdb WORKING POC
clocalmultiple
https://www.exploit-db.com/exploits/629

This PoC exploits multiple ZIP file parsing vulnerabilities (CAN-2004-0932 to CAN-2004-0937) by patching specific offsets in local and central headers to trigger flaws in various antivirus engines. It modifies ZIP files to create malformed headers that could bypass or crash affected software.

Classification
Working Poc 95%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: Multiple antivirus engines (McAfee, Computer Associates, Kaspersky, Sophos, Eset, RAV)
No auth needed
Prerequisites: A valid ZIP file to modify
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (7)

Core 7
Core References
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/13038/
Vendor Advisory vendor-advisory x_refsource_mandrake
http://www.mandriva.com/security/advisories?name=MDKSA-2004:118
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/17761
US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/492545
Exploit, Patch, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/11448
Patch, Vendor Advisory vendor-advisory x_refsource_gentoo
http://www.gentoo.org/security/en/glsa/glsa-200410-31.xml

Scores

EPSS 0.2025
EPSS Percentile 95.7%

Details

Status published
Products (46)
broadcom/brightstor_arcserve_backup 11.1
broadcom/etrust_antivirus 7.0
broadcom/etrust_antivirus 7.1
broadcom/etrust_antivirus_gateway 7.0
broadcom/etrust_antivirus_gateway 7.1
broadcom/etrust_ez_antivirus 6.1
broadcom/etrust_ez_antivirus 6.2
broadcom/etrust_ez_antivirus 6.3
broadcom/etrust_ez_armor 2.0
broadcom/etrust_ez_armor 2.3
... and 36 more
Published Jan 10, 2005
Tracked Since Feb 18, 2026