Lucene search

K
cve[email protected]CVE-2012-1420
HistoryMar 21, 2012 - 10:11 a.m.

CVE-2012-1420

2012-03-2110:11:47
CWE-264
web.nvd.nist.gov
23
cve-2012-1420
quick heal
command antivirus
f-prot antivirus
fortinet antivirus
k7 antivirus
kaspersky anti-virus
microsoft security essentials
nod32 antivirus
norman antivirus
panda antivirus
rising antivirus

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

6.6 Medium

AI Score

Confidence

Low

0.97 High

EPSS

Percentile

99.8%

The TAR file parser in Quick Heal (aka Cat QuickHeal) 11.00, Command Antivirus 5.2.11.5, F-Prot Antivirus 4.6.2.117, Fortinet Antivirus 4.2.254.0, K7 AntiVirus 9.77.3565, Kaspersky Anti-Virus 7.0.0.125, Antimalware Engine 1.1.6402.0 in Microsoft Security Essentials 2.0, NOD32 Antivirus 5795, Norman Antivirus 6.06.12, Panda Antivirus 10.0.2.7, and Rising Antivirus 22.83.00.03 allows remote attackers to bypass malware detection via a POSIX TAR file with an initial \7fELF character sequence. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.

Affected configurations

NVD
Node
authentiumcommand_antivirusMatch5.2.11.5
OR
catquick_healMatch11.00
OR
esetnod32_antivirusMatch5795
OR
f-protf-prot_antivirusMatch4.6.2.117
OR
fortinetfortinet_antivirusMatch4.2.254.0
OR
k7computingantivirusMatch9.77.3565
OR
kasperskykaspersky_anti-virusMatch7.0.0.125
OR
microsoftsecurity_essentialsMatch2.0
OR
normannorman_antivirus_\&_antispywareMatch6.06.12
OR
pandasecuritypanda_antivirusMatch10.0.2.7
OR
rising-globalrising_antivirusMatch22.83.00.03

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

6.6 Medium

AI Score

Confidence

Low

0.97 High

EPSS

Percentile

99.8%

Related for CVE-2012-1420