// For flags

CVE-2012-1429

 

Severity Score

4.3
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The ELF file parser in Bitdefender 7.2, Comodo Antivirus 7424, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, F-Secure Anti-Virus 9.0.16160.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwasher) 2010.1C, and nProtect Anti-Virus 2011-01-17.01 allows remote attackers to bypass malware detection via an ELF file with a ustar character sequence at a certain location. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different ELF parser implementations.

El analizador de archivos ELF en BitDefender 7.2, Comodo Antivirus 7424, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, F-Secure Anti-Virus 9.0.16160.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, McAfee Anti-Virus motor de Detección de 5.400.0.1158, McAfee gateway (anteriormente Webwasher) 2010.1C y nProtect anti-Virus 2011-01-17.01 permite a atacantes remotos evitar la detección de malware a través de un archivo ELF con una secuencia de caracteres ustar en un lugar determinado. NOTA: esto más adelante se puede dividir en varios CVEs si la información adicional que se publica muestra que el error se produjo de forma independiente en diferentes implementaciones del analizador. ELF

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
None
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2012-02-29 CVE Reserved
  • 2012-03-19 CVE Published
  • 2024-08-06 CVE Updated
  • 2024-11-09 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-264: Permissions, Privileges, and Access Controls
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Aladdin
Search vendor "Aladdin"
Esafe
Search vendor "Aladdin" for product "Esafe"
7.0.17.0
Search vendor "Aladdin" for product "Esafe" and version "7.0.17.0"
-
Affected
Comodo
Search vendor "Comodo"
Comodo Antivirus
Search vendor "Comodo" for product "Comodo Antivirus"
7424
Search vendor "Comodo" for product "Comodo Antivirus" and version "7424"
-
Affected
Emsisoft
Search vendor "Emsisoft"
Anti-malware
Search vendor "Emsisoft" for product "Anti-malware"
5.1.0.1
Search vendor "Emsisoft" for product "Anti-malware" and version "5.1.0.1"
-
Affected
F-secure
Search vendor "F-secure"
F-secure Anti-virus
Search vendor "F-secure" for product "F-secure Anti-virus"
9.0.16160.0
Search vendor "F-secure" for product "F-secure Anti-virus" and version "9.0.16160.0"
-
Affected
Ikarus
Search vendor "Ikarus"
Ikarus Virus Utilities T3 Command Line Scanner
Search vendor "Ikarus" for product "Ikarus Virus Utilities T3 Command Line Scanner"
1.1.97.0
Search vendor "Ikarus" for product "Ikarus Virus Utilities T3 Command Line Scanner" and version "1.1.97.0"
-
Affected
Mcafee
Search vendor "Mcafee"
Gateway
Search vendor "Mcafee" for product "Gateway"
2010.1c
Search vendor "Mcafee" for product "Gateway" and version "2010.1c"
-
Affected
Mcafee
Search vendor "Mcafee"
Scan Engine
Search vendor "Mcafee" for product "Scan Engine"
5.400.0.1158
Search vendor "Mcafee" for product "Scan Engine" and version "5.400.0.1158"
-
Affected
Nprotect
Search vendor "Nprotect"
Nprotect Antivirus
Search vendor "Nprotect" for product "Nprotect Antivirus"
2011-01-17.01
Search vendor "Nprotect" for product "Nprotect Antivirus" and version "2011-01-17.01"
-
Affected
Softwin
Search vendor "Softwin"
Bitdefender
Search vendor "Softwin" for product "Bitdefender"
7.2
Search vendor "Softwin" for product "Bitdefender" and version "7.2"
-
Affected