Attacker Value
Unknown
(0 users assessed)
Exploitability
Unknown
(0 users assessed)
User Interaction
Unknown
Privileges Required
Unknown
Attack Vector
Unknown
0

CVE-2012-1457

Disclosure Date: March 21, 2012
Add MITRE ATT&CK tactics and techniques that apply to this CVE.

Description

The TAR file parser in Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8.1351.0 and 5.0.677.0, AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Quick Heal (aka Cat QuickHeal) 11.00, ClamAV 0.96.4, Command Antivirus 5.2.11.5, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, F-Prot Antivirus 4.6.2.117, G Data AntiVirus 21, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Jiangmin Antivirus 13.0.900, K7 AntiVirus 9.77.3565, Kaspersky Anti-Virus 7.0.0.125, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwasher) 2010.1C, Antimalware Engine 1.1.6402.0 in Microsoft Security Essentials 2.0, NOD32 Antivirus 5795, Norman Antivirus 6.06.12, PC Tools AntiVirus 7.0.3.5, Rising Antivirus 22.83.00.03, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Trend Micro AntiVirus 9.120.0.1004, Trend Micro HouseCall 9.120.0.1004, VBA32 3.12.14.2, and VirusBuster 13.6.151.0 allows remote attackers to bypass malware detection via a TAR archive entry with a length field that exceeds the total TAR file size. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.

Add Assessment

No one has assessed this topic. Be the first to add your voice to the community.

CVSS V3 Severity and Metrics
Base Score:
None
Impact Score:
Unknown
Exploitability Score:
Unknown
Vector:
Unknown
Attack Vector (AV):
Unknown
Attack Complexity (AC):
Unknown
Privileges Required (PR):
Unknown
User Interaction (UI):
Unknown
Scope (S):
Unknown
Confidentiality (C):
Unknown
Integrity (I):
Unknown
Availability (A):
Unknown

General Information

Vendors

  • aladdin,
  • alwil,
  • anti-virus,
  • antiy,
  • authentium,
  • avg,
  • avira,
  • bitdefender,
  • cat,
  • clamav,
  • emsisoft,
  • eset,
  • f-prot,
  • gdata-software,
  • ikarus,
  • jiangmin,
  • k7computing,
  • kaspersky,
  • mcafee,
  • microsoft,
  • norman,
  • pc tools,
  • rising-global,
  • symantec,
  • trendmicro,
  • virusbuster

Products

  • anti-malware 5.1.0.1,
  • antivir 7.11.1.163,
  • antivirus 9.77.3565,
  • avast antivirus 4.8.1351.0,
  • avast antivirus 5.0.677.0,
  • avg anti-virus 10.0.0.1190,
  • avl sdk 2.0.3.7,
  • bitdefender 7.2,
  • clamav 0.96.4,
  • command antivirus 5.2.11.5,
  • endpoint protection 11.0,
  • esafe 7.0.17.0,
  • f-prot antivirus 4.6.2.117,
  • g data antivirus 21,
  • gateway 2010.1c,
  • housecall 9.120.0.1004,
  • ikarus virus utilities t3 command line scanner 1.1.97.0,
  • jiangmin antivirus 13.0.900,
  • kaspersky anti-virus 7.0.0.125,
  • nod32 antivirus 5795,
  • norman antivirus & antispyware 6.06.12,
  • pc tools antivirus 7.0.3.5,
  • quick heal 11.00,
  • rising antivirus 22.83.00.03,
  • scan engine 5.400.0.1158,
  • security essentials 2.0,
  • trend micro antivirus 9.120.0.1004,
  • vba32 3.12.14.2,
  • virusbuster 13.6.151.0
Technical Analysis