PT-2012-3275 · Emsisoft+2 · Emsisoft Anti-Malware+2
Published
2012-03-21
·
Updated
2012-07-28
·
CVE-2012-1450
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Emsisoft Anti-Malware version 5.1.0.1
Sophos Anti-Virus version 4.61.0
Ikarus Virus Utilities T3 Command Line Scanner version 1.1.97.0
Description
The issue allows remote attackers to bypass malware detection via a CAB file with a modified
reserved3 field. This could potentially be exploited in different CAB parser implementations.Recommendations
For Emsisoft Anti-Malware version 5.1.0.1, consider updating to a newer version that addresses the CAB file parser issue.
For Sophos Anti-Virus version 4.61.0, consider updating to a newer version that addresses the CAB file parser issue.
For Ikarus Virus Utilities T3 Command Line Scanner version 1.1.97.0, consider updating to a newer version that addresses the CAB file parser issue.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Emsisoft Anti-Malware
Ikarus Virus Utilities T3 Command Line Scanner
Sophos Anti-Virus