PT-2012-3278 · Antiy+12 · Antiy Labs Avl Sdk+13

Published

2012-03-21

·

Updated

2012-11-06

·

CVE-2012-1453

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Dr.Web version 5.0.2.03300 Trend Micro HouseCall versions 9.120.0.1004 Kaspersky Anti-Virus version 7.0.0.125 Sophos Anti-Virus version 4.61.0 Trend Micro AntiVirus version 9.120.0.1004 McAfee Gateway version 2010.1C Emsisoft Anti-Malware version 5.1.0.1 CA eTrust Vet Antivirus version 36.1.8511 Antiy Labs AVL SDK version 2.0.3.7 Microsoft Security Essentials version 2.0 Rising Antivirus version 22.83.00.03 Ikarus Virus Utilities T3 Command Line Scanner version 1.1.97.0 Fortinet Antivirus version 4.2.254.0 Panda Antivirus version 10.0.2.7
Description The CAB file parser in the affected software allows remote attackers to bypass malware detection via a CAB file with a modified coffFiles field.
Recommendations For Dr.Web version 5.0.2.03300, update to a newer version that contains a fix for this issue. For Trend Micro HouseCall version 9.120.0.1004, update to a newer version that contains a fix for this issue. For Kaspersky Anti-Virus version 7.0.0.125, update to a newer version that contains a fix for this issue. For Sophos Anti-Virus version 4.61.0, update to a newer version that contains a fix for this issue. For Trend Micro AntiVirus version 9.120.0.1004, update to a newer version that contains a fix for this issue. For McAfee Gateway version 2010.1C, update to a newer version that contains a fix for this issue. For Emsisoft Anti-Malware version 5.1.0.1, update to a newer version that contains a fix for this issue. For CA eTrust Vet Antivirus version 36.1.8511, update to a newer version that contains a fix for this issue. For Antiy Labs AVL SDK version 2.0.3.7, update to a newer version that contains a fix for this issue. For Microsoft Security Essentials version 2.0, update to a newer version that contains a fix for this issue. For Rising Antivirus version 22.83.00.03, update to a newer version that contains a fix for this issue. For Ikarus Virus Utilities T3 Command Line Scanner version 1.1.97.0, update to a newer version that contains a fix for this issue. For Fortinet Antivirus version 4.2.254.0, update to a newer version that contains a fix for this issue. For Panda Antivirus version 10.0.2.7, update to a newer version that contains a fix for this issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-1453

Affected Products

Antiy Labs Avl Sdk
Ca Etrust Vet Antivirus
Dr.Web
Emsisoft Anti-Malware
Fortinet Antivirus
Ikarus Virus Utilities T3 Command Line Scanner
Kaspersky Anti-Virus
Mcafee Gateway
Security Essentials
Panda Antivirus
Rising Antivirus
Sophos Anti-Virus
Trend Micro Antivirus
Trend Micro Housecall