CVE-2012-1424
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The TAR file parser in Antiy Labs AVL SDK 2.0.3.7, Quick Heal (aka Cat QuickHeal) 11.00, Jiangmin Antivirus 13.0.900, Norman Antivirus 6.06.12, PC Tools AntiVirus 7.0.3.5, and Sophos Anti-Virus 4.61.0 allows remote attackers to bypass malware detection via a POSIX TAR file with a \19\04\00\10 character sequence at a certain location. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.
El analizador de archivos TAR en Antiy Labs AVL SDK 2.0.3.7, Quick Heal (también conocido como Cat QuickHeal) 11.00, Jiangmin Antivirus 13.0.900, Norman Antivirus 6.6.12, PC Tools AntiVirus 7.0.3.5, y Sophos Anti-Virus 4.61.0 permite a atacantes remotos evitar la detección de malware a través de un archivo POSIX TAR con una secuencia de caracteres \19\04\00\10 en un lugar determinado. NOTA: esto más adelante se puede dividir en varios CVEs si la información adicional que se publica muestra que el error se produjo de forma independiente en diferentes implementaciones del analizador TAR.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2012-02-29 CVE Reserved
- 2012-03-19 CVE Published
- 2024-08-06 CVE Updated
- 2024-09-19 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-264: Permissions, Privileges, and Access Controls
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
http://osvdb.org/80390 | Vdb Entry | |
http://osvdb.org/80391 | Vdb Entry | |
http://osvdb.org/80392 | Vdb Entry | |
http://osvdb.org/80409 | Vdb Entry | |
http://www.ieee-security.org/TC/SP2012/program.html | X_refsource_misc | |
http://www.securityfocus.com/archive/1/522005 | Mailing List |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Antiy Search vendor "Antiy" | Avl Sdk Search vendor "Antiy" for product "Avl Sdk" | 2.0.3.7 Search vendor "Antiy" for product "Avl Sdk" and version "2.0.3.7" | - |
Affected
| ||||||
Cat Search vendor "Cat" | Quick Heal Search vendor "Cat" for product "Quick Heal" | 11.00 Search vendor "Cat" for product "Quick Heal" and version "11.00" | - |
Affected
| ||||||
Jiangmin Search vendor "Jiangmin" | Jiangmin Antivirus Search vendor "Jiangmin" for product "Jiangmin Antivirus" | 13.0.900 Search vendor "Jiangmin" for product "Jiangmin Antivirus" and version "13.0.900" | - |
Affected
| ||||||
Norman Search vendor "Norman" | Norman Antivirus \& Antispyware Search vendor "Norman" for product "Norman Antivirus \& Antispyware" | 6.06.12 Search vendor "Norman" for product "Norman Antivirus \& Antispyware" and version "6.06.12" | - |
Affected
| ||||||
Pc Tools Search vendor "Pc Tools" | Pc Tools Antivirus Search vendor "Pc Tools" for product "Pc Tools Antivirus" | 7.0.3.5 Search vendor "Pc Tools" for product "Pc Tools Antivirus" and version "7.0.3.5" | - |
Affected
| ||||||
Sophos Search vendor "Sophos" | Sophos Anti-virus Search vendor "Sophos" for product "Sophos Anti-virus" | 4.61.0 Search vendor "Sophos" for product "Sophos Anti-virus" and version "4.61.0" | - |
Affected
|