Vulnerability Name: | CVE-2012-1423 (CCN-74205) | ||||||||
Assigned: | 2012-03-19 | ||||||||
Published: | 2012-03-19 | ||||||||
Updated: | 2012-08-14 | ||||||||
Summary: | The TAR file parser in Command Antivirus 5.2.11.5, Emsisoft Anti-Malware 5.1.0.1, F-Prot Antivirus 4.6.2.117, Fortinet Antivirus 4.2.254.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, K7 AntiVirus 9.77.3565, NOD32 Antivirus 5795, Norman Antivirus 6.06.12, PC Tools AntiVirus 7.0.3.5, Rising Antivirus 22.83.00.03, and VirusBuster 13.6.151.0 allows remote attackers to bypass malware detection via a POSIX TAR file with an initial MZ character sequence. Note: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N) 3.5 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:U/RL:U/RC:UR)
3.5 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:U/RL:U/RC:UR)
| ||||||||
Vulnerability Type: | CWE-264 | ||||||||
Vulnerability Consequences: | Bypass Security | ||||||||
References: | Source: CCN Type: BugTraq Mailing List, Sun Mar 18 2012 Evasion attacks expoliting file-parsing vulnerabilities in antivirus products Source: MITRE Type: CNA CVE-2012-1423 Source: OSVDB Type: UNKNOWN 80393 Source: OSVDB Type: UNKNOWN 80395 Source: OSVDB Type: UNKNOWN 80396 Source: OSVDB Type: UNKNOWN 80406 Source: OSVDB Type: UNKNOWN 80407 Source: CCN Type: Command Web Site Antivirus | Commtouch - Internet Security Solutions Source: CCN Type: Emsisoft Web Site Emsisoft Anti-Malware Source: CCN Type: ESET Web Site ESET - Antivirus Software with Spyware and Malware Protection Source: CCN Type: F-Prot Web Site F-Prot Antivirus Source: CCN Type: Fortinet Web Site Fortinet Antivirus Source: MISC Type: UNKNOWN http://www.ieee-security.org/TC/SP2012/program.html Source: CCN Type: Ikarus Web Site Ikarus Security Software Source: CCN Type: K7 Web Site K7 Antivirus Source: CCN Type: Norman Web Site Antivirus | Norman Proactive IT security Source: CCN Type: OSVDB ID: 80393 VirusBuster Malformed TAR File Handling Scan Bypass Source: CCN Type: OSVDB ID: 80394 PC Tools AntiVirus Malformed TAR File Handling Scan Bypass Source: CCN Type: OSVDB ID: 80395 Ikarus Virus Utilities T3 Command Line Scanner Malformed TAR File Handling Scan Bypass Source: CCN Type: OSVDB ID: 80396 Emsisoft Anti-Malware Malformed TAR File Handling Scan Bypass Source: CCN Type: OSVDB ID: 80406 F-Prot Antivirus Malformed TAR File Handling Scan Bypass Source: CCN Type: OSVDB ID: 80407 Command Antivirus Malformed TAR File Handling Scan Bypass Source: CCN Type: PC Tools Web Site PC Tools Antivirus Source: CCN Type: Rising Web Site Rising Antivirus Source: BUGTRAQ Type: UNKNOWN 20120319 Evasion attacks expoliting file-parsing vulnerabilities in antivirus products Source: CCN Type: BID-52588 Multiple AntiVirus Products CVE-2012-1423 TAR File Scan Evasion Vulnerability Source: CCN Type: VirusBuster Web Site VirusBuster Source: XF Type: UNKNOWN multiple-av-tar-mz-evasion(74205) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |