PT-2012-3244 · Cisco+1 · Clamav+1
Publicado
2012-03-21
·
Atualizado
2012-08-14
·
CVE-2012-1419
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
ClamAV version 0.96.4
Quick Heal version 11.00
Description
The issue concerns the TAR file parser, which allows remote attackers to bypass malware detection. This is achieved by using a POSIX TAR file that contains an initial
[aliases] character sequence.Recommendations
For ClamAV version 0.96.4, update to a newer version that addresses this issue.
For Quick Heal version 11.00, update to a newer version that addresses this issue.
As a temporary workaround, consider restricting the use of TAR file parsing functionality until a patch is available.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Clamav
Quick Heal