Vulnerability Name: | CVE-2012-1421 (CCN-74200) | ||||||||
Assigned: | 2012-03-19 | ||||||||
Published: | 2012-03-19 | ||||||||
Updated: | 2012-12-20 | ||||||||
Summary: | The TAR file parser in Quick Heal (aka Cat QuickHeal) 11.00, Norman Antivirus 6.06.12, Rising Antivirus 22.83.00.03, and AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11 allows remote attackers to bypass malware detection via a POSIX TAR file with an initial MSCF character sequence. Note: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N) 3.5 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:U/RL:U/RC:UR)
3.5 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:U/RL:U/RC:UR)
| ||||||||
Vulnerability Type: | CWE-264 | ||||||||
Vulnerability Consequences: | Bypass Security | ||||||||
References: | Source: CCN Type: BugTraq Mailing List, Sun Mar 18 2012 Evasion attacks expoliting file-parsing vulnerabilities in antivirus products Source: MITRE Type: CNA CVE-2012-1421 Source: OSVDB Type: UNKNOWN 80409 Source: MISC Type: UNKNOWN http://www.ieee-security.org/TC/SP2012/program.html Source: CCN Type: Norman Web Site Antivirus | Norman Proactive IT security Source: CCN Type: OSVDB ID: 80397 Symantec Endpoint Protection AVEngine Malformed TAR File Handling Scan Bypass Source: CCN Type: OSVDB ID: 80409 Quick Heal Malformed TAR File Handling Scan Bypass Source: CCN Type: Quick Heal Web Site Quick Heal Antivirus Source: CCN Type: Rising Web Site Rising Antivirus Source: BUGTRAQ Type: UNKNOWN 20120319 Evasion attacks expoliting file-parsing vulnerabilities in antivirus products Source: CCN Type: BID-52575 Multiple AntiVirus Products 'TAR' File Scan Evasion Vulnerability Source: CCN Type: Symantec Web Site Symantec Antivirus Source: XF Type: UNKNOWN multiple-av-tar-mscf-evasion(74200) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |