Lucene search

K
nvd[email protected]NVD:CVE-2012-1419
HistoryMar 21, 2012 - 10:11 a.m.

CVE-2012-1419

2012-03-2110:11:47
CWE-264
web.nvd.nist.gov
7

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

6.3

Confidence

Low

EPSS

0.912

Percentile

98.9%

The TAR file parser in ClamAV 0.96.4 and Quick Heal (aka Cat QuickHeal) 11.00 allows remote attackers to bypass malware detection via a POSIX TAR file with an initial [aliases] character sequence. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.

Affected configurations

Nvd
Node
catquick_healMatch11.00
OR
clamavclamavMatch0.96.4
VendorProductVersionCPE
catquick_heal11.00cpe:2.3:a:cat:quick_heal:11.00:*:*:*:*:*:*:*
clamavclamav0.96.4cpe:2.3:a:clamav:clamav:0.96.4:*:*:*:*:*:*:*

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

6.3

Confidence

Low

EPSS

0.912

Percentile

98.9%