CVE-2012-1420
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The TAR file parser in Quick Heal (aka Cat QuickHeal) 11.00, Command Antivirus 5.2.11.5, F-Prot Antivirus 4.6.2.117, Fortinet Antivirus 4.2.254.0, K7 AntiVirus 9.77.3565, Kaspersky Anti-Virus 7.0.0.125, Antimalware Engine 1.1.6402.0 in Microsoft Security Essentials 2.0, NOD32 Antivirus 5795, Norman Antivirus 6.06.12, Panda Antivirus 10.0.2.7, and Rising Antivirus 22.83.00.03 allows remote attackers to bypass malware detection via a POSIX TAR file with an initial \7fELF character sequence. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.
El analizador de archivos TAR en Quick Heal (también conocido como Cat QuickHeal) 11.00, Command Antivirus 5.2.11.5, F-Prot Antivirus 4.6.2.117, Fortinet Antivirus 4.2.254.0, K7 AntiVirus 9.77.3565, Kaspersky Anti-Virus 7.0.0.125, Antimalware Engine 1.1.6402.0 en el Microsoft Security Essentials 2.0, NOD32 Antivirus 5795, Norman Antivirus 6.6.12, Panda Antivirus 10.0.2.7, y Rising Antivirus 22.83.00.03 permite a atacantes remotos evitar la detección de malware a través de un archivo TAR POSIX con una secuencia de caracteres inicial \ 7fELF . NOTA: esto más adelante se puede dividir en varios CVEs si la información adicional que se publica muestra que el error se produjo de forma independiente en diferentes implementaciones del analizador TAR.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2012-02-29 CVE Reserved
- 2012-03-19 CVE Published
- 2024-08-06 CVE Updated
- 2024-09-19 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-264: Permissions, Privileges, and Access Controls
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
http://osvdb.org/80403 | Vdb Entry | |
http://osvdb.org/80406 | Vdb Entry | |
http://osvdb.org/80407 | Vdb Entry | |
http://osvdb.org/80409 | Vdb Entry | |
http://www.ieee-security.org/TC/SP2012/program.html | X_refsource_misc | |
http://www.securityfocus.com/archive/1/522005 | Mailing List |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Authentium Search vendor "Authentium" | Command Antivirus Search vendor "Authentium" for product "Command Antivirus" | 5.2.11.5 Search vendor "Authentium" for product "Command Antivirus" and version "5.2.11.5" | - |
Affected
| ||||||
Cat Search vendor "Cat" | Quick Heal Search vendor "Cat" for product "Quick Heal" | 11.00 Search vendor "Cat" for product "Quick Heal" and version "11.00" | - |
Affected
| ||||||
Eset Search vendor "Eset" | Nod32 Antivirus Search vendor "Eset" for product "Nod32 Antivirus" | 5795 Search vendor "Eset" for product "Nod32 Antivirus" and version "5795" | - |
Affected
| ||||||
F-prot Search vendor "F-prot" | F-prot Antivirus Search vendor "F-prot" for product "F-prot Antivirus" | 4.6.2.117 Search vendor "F-prot" for product "F-prot Antivirus" and version "4.6.2.117" | - |
Affected
| ||||||
Fortinet Search vendor "Fortinet" | Fortinet Antivirus Search vendor "Fortinet" for product "Fortinet Antivirus" | 4.2.254.0 Search vendor "Fortinet" for product "Fortinet Antivirus" and version "4.2.254.0" | - |
Affected
| ||||||
K7computing Search vendor "K7computing" | Antivirus Search vendor "K7computing" for product "Antivirus" | 9.77.3565 Search vendor "K7computing" for product "Antivirus" and version "9.77.3565" | - |
Affected
| ||||||
Kaspersky Search vendor "Kaspersky" | Kaspersky Anti-virus Search vendor "Kaspersky" for product "Kaspersky Anti-virus" | 7.0.0.125 Search vendor "Kaspersky" for product "Kaspersky Anti-virus" and version "7.0.0.125" | - |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Security Essentials Search vendor "Microsoft" for product "Security Essentials" | 2.0 Search vendor "Microsoft" for product "Security Essentials" and version "2.0" | - |
Affected
| ||||||
Norman Search vendor "Norman" | Norman Antivirus \& Antispyware Search vendor "Norman" for product "Norman Antivirus \& Antispyware" | 6.06.12 Search vendor "Norman" for product "Norman Antivirus \& Antispyware" and version "6.06.12" | - |
Affected
| ||||||
Pandasecurity Search vendor "Pandasecurity" | Panda Antivirus Search vendor "Pandasecurity" for product "Panda Antivirus" | 10.0.2.7 Search vendor "Pandasecurity" for product "Panda Antivirus" and version "10.0.2.7" | - |
Affected
| ||||||
Rising-global Search vendor "Rising-global" | Rising Antivirus Search vendor "Rising-global" for product "Rising Antivirus" | 22.83.00.03 Search vendor "Rising-global" for product "Rising Antivirus" and version "22.83.00.03" | - |
Affected
|