// For flags

CVE-2012-1460

 

Severity Score

4.3
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The Gzip file parser in Antiy Labs AVL SDK 2.0.3.7, Quick Heal (aka Cat QuickHeal) 11.00, Command Antivirus 5.2.11.5, eSafe 7.0.17.0, F-Prot Antivirus 4.6.2.117, Jiangmin Antivirus 13.0.900, K7 AntiVirus 9.77.3565, and VBA32 3.12.14.2 allows remote attackers to bypass malware detection via a .tar.gz file with stray bytes at the end. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different Gzip parser implementations.

El analizador de archivos Gzip en Antiy Labs AVL SDK v2.0.3.7, Quick Heal (también conocido como Cat QuickHeal) v11.00, Command Antivirus v5.2.11.5, v7.0.17.0 eSafe, F-Prot Antivirus v4.6.2.117, Jiangmin Antivirus v13.0.900, K7 AntiVirus 9.77.3565, y VBA32 v3.12.14.2 permite a atacantes remotos evitar la detección de malware a través de un archivo. tar.gz con los bytes extraviados al final. NOTA: esto más adelante se puede dividir en varios CVEs si la información adicional que se publica muestra que el error se produjo de forma independiente en diferentes implementaciones del analizador Gzip.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
None
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2012-02-29 CVE Reserved
  • 2012-03-21 CVE Published
  • 2024-08-06 CVE Updated
  • 2024-09-19 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-264: Permissions, Privileges, and Access Controls
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Aladdin
Search vendor "Aladdin"
Esafe
Search vendor "Aladdin" for product "Esafe"
7.0.17.0
Search vendor "Aladdin" for product "Esafe" and version "7.0.17.0"
-
Affected
Anti-virus
Search vendor "Anti-virus"
Vba32
Search vendor "Anti-virus" for product "Vba32"
3.12.14.2
Search vendor "Anti-virus" for product "Vba32" and version "3.12.14.2"
-
Affected
Antiy
Search vendor "Antiy"
Avl Sdk
Search vendor "Antiy" for product "Avl Sdk"
2.0.3.7
Search vendor "Antiy" for product "Avl Sdk" and version "2.0.3.7"
-
Affected
Authentium
Search vendor "Authentium"
Command Antivirus
Search vendor "Authentium" for product "Command Antivirus"
5.2.11.5
Search vendor "Authentium" for product "Command Antivirus" and version "5.2.11.5"
-
Affected
Cat
Search vendor "Cat"
Quick Heal
Search vendor "Cat" for product "Quick Heal"
11.00
Search vendor "Cat" for product "Quick Heal" and version "11.00"
-
Affected
F-prot
Search vendor "F-prot"
F-prot Antivirus
Search vendor "F-prot" for product "F-prot Antivirus"
4.6.2.117
Search vendor "F-prot" for product "F-prot Antivirus" and version "4.6.2.117"
-
Affected
Jiangmin
Search vendor "Jiangmin"
Jiangmin Antivirus
Search vendor "Jiangmin" for product "Jiangmin Antivirus"
13.0.900
Search vendor "Jiangmin" for product "Jiangmin Antivirus" and version "13.0.900"
-
Affected
K7computing
Search vendor "K7computing"
Antivirus
Search vendor "K7computing" for product "Antivirus"
9.77.3565
Search vendor "K7computing" for product "Antivirus" and version "9.77.3565"
-
Affected