Vulnerability record · CVE-2004-0964 · published 9 February 2005
CVE-2004-0964: Zinf .pls playlist buffer overflow allows code execution
Zinf · Zinf
Zinf 2.2.1 on Windows and older Linux versions contain a buffer overflow triggered by certain values in a .pls playlist file. Because the flaw is remotely reachable and rated AV:N/AC:L/Au:N with full confidentiality, integrity and availability impact, it matters as a potential full-compromise vector on any host running the affected player.
Description
Buffer overflow in Zinf 2.2.1 on Windows, and other older versions for Linux, allows remote attackers or local users to execute arbitrary code via certain values in a .pls file.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
high priorityRemote, unauthenticated code execution with complete impact and public exploit references, though the product is legacy and no KEV listing exists.
What it is
Zinf 2.2.1 on Windows and older Linux versions contain a buffer overflow triggered by certain values in a .pls playlist file. Because the flaw is remotely reachable and rated AV:N/AC:L/Au:N with full confidentiality, integrity and availability impact, it matters as a potential full-compromise vector on any host running the affected player.
Impact
An attacker can execute arbitrary code with the privileges of the Zinf process, giving full control of the host or user session. The CVSS 2.0 vector indicates complete loss of confidentiality, integrity and availability.
Attack surface
Reached by supplying a crafted .pls file, either remotely (e.g. a downloaded or linked playlist) or by a local user. No authentication is required per the AV:N/Au:N vector, but opening or loading the malicious playlist requires some user action.
Exploitation
Not listed in CISA KEV and no ransomware association is recorded, but EPSS is 0.62678 (99.155th percentile) and SecurityFocus BID 11248 carries an Exploit tag, indicating public exploit material exists.
What to do
- Upgrade or remove Zinf; the Debian advisory DSA-587 provides the vendor patch for affected Debian packages.
- Apply the vendor fix referenced in DSA-587 and SecurityFocus BID 11248 before any other action.
- Block or strip .pls files at email and web gateways where Zinf is still deployed.
- Restrict execution of Zinf to trusted users and remove it from systems where it is not required.
- Monitor for unexpected child processes or network connections spawned by the Zinf binary.
Detection
- Alert on Zinf processes spawning shells or unexpected child processes.
- Inspect .pls files for oversized or malformed entries before they reach the player.
- Hunt for Zinf crashes or access violations in endpoint logs that correlate with playlist opening.
- Review proxy and email logs for .pls attachments or downloads directed at hosts with Zinf installed.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2004-0964 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2004-0964), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.