Vulnerability Name: | CVE-2012-1440 (CCN-74255) | ||||||||
Assigned: | 2012-03-19 | ||||||||
Published: | 2012-03-19 | ||||||||
Updated: | 2012-03-21 | ||||||||
Summary: | The ELF file parser in Norman Antivirus 6.06.12, eSafe 7.0.17.0, CA eTrust Vet Antivirus 36.1.8511, Fortinet Antivirus 4.2.254.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an ELF file with a modified identsize field. Note: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different ELF parser implementations. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N) 3.5 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:U/RL:U/RC:UR)
3.5 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:U/RL:U/RC:UR)
| ||||||||
Vulnerability Type: | CWE-264 | ||||||||
Vulnerability Consequences: | Bypass Security | ||||||||
References: | Source: CCN Type: BugTraq Mailing List, Sun Mar 18 2012 Evasion attacks expoliting file-parsing vulnerabilities in antivirus products Source: MITRE Type: CNA CVE-2012-1440 Source: CCN Type: Fortinet Web Site Fortinet Antivirus Source: MISC Type: UNKNOWN http://www.ieee-security.org/TC/SP2012/program.html Source: CCN Type: Norman Web Site Norman Antivirus Source: CCN Type: OSVDB ID: 80424 Norman Antivirus Malformed ELF File Handling Scan Bypass Source: CCN Type: OSVDB ID: 80425 CA eTrust Vet Antivirus Malformed ELF File Handling Scan Bypass Source: CCN Type: Panda Web Site Panda Antivirus Source: CCN Type: eSafe Web Site SafeNet eSafe Antivirus Source: BUGTRAQ Type: UNKNOWN 20120319 Evasion attacks expoliting file-parsing vulnerabilities in antivirus products Source: CCN Type: BID-52595 Multiple AntiVirus Products CVE-2012-1440 ELF File Scan Evasion Vulnerability Source: CCN Type: eTrust-Vet Web Site eTrust-Vet Antivirus Source: XF Type: UNKNOWN multiple-av-elf-identsize-evasion(74255) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |