ID

VAR-201203-0147


CVE

CVE-2012-1462


TITLE

Multiple products ZIP Vulnerability that prevents file parsers from detecting malware

Trust: 0.8

sources: JVNDB: JVNDB-2012-001871

DESCRIPTION

The ZIP file parser in AhnLab V3 Internet Security 2011.01.18.00, AVG Anti-Virus 10.0.0.1190, Quick Heal (aka Cat QuickHeal) 11.00, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, Fortinet Antivirus 4.2.254.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Jiangmin Antivirus 13.0.900, Kaspersky Anti-Virus 7.0.0.125, Norman Antivirus 6.06.12, Sophos Anti-Virus 4.61.0, and AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11 allows remote attackers to bypass malware detection via a ZIP file containing an invalid block of data at the beginning. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different ZIP parser implementations. Multiple products ZIP A file parser contains a vulnerability that can prevent malware detection. Different ZIP Parser If it is announced that there is also a problem with the implementation of CVE May be split.A third party includes an invalid block of data at the beginning ZIP Malware detection may be avoided via files. Successful exploits will allow attackers to bypass on-demand virus scanning, possibly allowing malicious files to escape detection

Trust: 1.98

sources: NVD: CVE-2012-1462 // JVNDB: JVNDB-2012-001871 // BID: 52613 // VULHUB: VHN-54743

AFFECTED PRODUCTS

vendor:avgmodel:anti-virusscope:eqversion:10.0.0.1190

Trust: 1.8

vendor:emsisoftmodel:anti-malwarescope:eqversion:5.1.0.1

Trust: 1.8

vendor:ikarusmodel:virus utilities t3 command line scannerscope:eqversion:1.1.97.0

Trust: 1.8

vendor:jiangminmodel:antivirusscope:eqversion:13.0.900

Trust: 1.8

vendor:aladdinmodel:esafescope:eqversion:7.0.17.0

Trust: 1.8

vendor:kasperskymodel:anti-virusscope:eqversion:7.0.0.125

Trust: 1.8

vendor:fortinetmodel:antivirusscope:eqversion:4.2.254.0

Trust: 1.8

vendor:symantecmodel:endpoint protectionscope:eqversion:11.0

Trust: 1.6

vendor:ahnlabmodel:v3 internet securityscope:eqversion:2011.01.18.00

Trust: 1.0

vendor:catmodel:quick healscope:eqversion:11.00

Trust: 1.0

vendor:normanmodel:antivirusscope:eqversion:6.06.12

Trust: 0.8

vendor:unlabmodel:v3 internet securityscope:eqversion:2011.01.18.00

Trust: 0.8

vendor:quick heal k kmodel:healscope:eqversion:11.00

Trust: 0.8

vendor:symantecmodel:endpoint protectionscope:eqversion:11

Trust: 0.8

vendor:sophosmodel:anti-virusscope:eqversion:4.61.0

Trust: 0.8

vendor:symantecmodel:antivirusscope:eqversion:20101.3103

Trust: 0.3

vendor:sophosmodel:anti-virusscope:eqversion:4.61

Trust: 0.3

vendor:quick healmodel:cat-quickhealscope:eqversion:11.00

Trust: 0.3

vendor:normanmodel:antivirusscope:eqversion:6.6.12

Trust: 0.3

vendor:kasperskymodel:antivirusscope:eqversion:7.0125

Trust: 0.3

vendor:jiangminmodel:jiangminscope:eqversion:13.0.900

Trust: 0.3

vendor:ikarusmodel:antivirus t3.1.1.97.0scope: - version: -

Trust: 0.3

vendor:fortinetmodel:antivirusscope:eqversion:4.2.2540

Trust: 0.3

vendor:esafemodel:antivirusscope:eqversion:7.0.170

Trust: 0.3

vendor:emsisoftmodel:antivirusscope:eqversion:5.11

Trust: 0.3

vendor:avgmodel:anti-virusscope:eqversion:10.01190

Trust: 0.3

vendor:ahnlabmodel:enginescope:eqversion:v32011.01.18.00

Trust: 0.3

sources: BID: 52613 // JVNDB: JVNDB-2012-001871 // CNNVD: CNNVD-201203-425 // NVD: CVE-2012-1462

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2012-1462
value: MEDIUM

Trust: 1.0

NVD: CVE-2012-1462
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-201203-425
value: MEDIUM

Trust: 0.6

VULHUB: VHN-54743
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2012-1462
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-54743
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-54743 // JVNDB: JVNDB-2012-001871 // CNNVD: CNNVD-201203-425 // NVD: CVE-2012-1462

PROBLEMTYPE DATA

problemtype:CWE-264

Trust: 1.9

sources: VULHUB: VHN-54743 // JVNDB: JVNDB-2012-001871 // NVD: CVE-2012-1462

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201203-425

TYPE

permissions and access control

Trust: 0.6

sources: CNNVD: CNNVD-201203-425

CONFIGURATIONS

sources: JVNDB: JVNDB-2012-001871

PATCH

title:AVG Anti-Virusurl:http://www.avgjapan.com/home-small-office-security/buy-antivirus

Trust: 0.8

title:Emsisoft Anti-Malwareurl:http://www.emsisoft.com/en/software/antimalware/

Trust: 0.8

title:Fortinet Antivirusurl:http://www.fortinet.com/solutions/antivirus.html

Trust: 0.8

title:Top Pageurl:http://www.ikarus.at/en/

Trust: 0.8

title:Jiangmin Antivirusurl:http://global.jiangmin.com/

Trust: 0.8

title:Top Pageurl:http://www.norman.com/

Trust: 0.8

title:Quick Healurl:http://www.quickheal.com/

Trust: 0.8

title:Endpoint Protectionurl:http://www.symantec.com/ja/jp/endpoint-protection

Trust: 0.8

title:eSafeurl:http://www.aladdin.co.jp/esafe/

Trust: 0.8

title:V3 Internet Securityurl:http://www.ahnlab.co.jp/product_service/product/b2b/v3is8.asp

Trust: 0.8

title:Kaspersky Anti-Virusurl:http://www.kaspersky.com/kaspersky_anti-virus

Trust: 0.8

title:Top Pageurl:http://www.sophos.com

Trust: 0.8

sources: JVNDB: JVNDB-2012-001871

EXTERNAL IDS

db:NVDid:CVE-2012-1462

Trust: 2.8

db:BIDid:52613

Trust: 1.4

db:JVNDBid:JVNDB-2012-001871

Trust: 0.8

db:CNNVDid:CNNVD-201203-425

Trust: 0.7

db:BUGTRAQid:20120319 EVASION ATTACKS EXPOLITING FILE-PARSING VULNERABILITIES IN ANTIVIRUS PRODUCTS

Trust: 0.6

db:NSFOCUSid:19217

Trust: 0.6

db:VULHUBid:VHN-54743

Trust: 0.1

sources: VULHUB: VHN-54743 // BID: 52613 // JVNDB: JVNDB-2012-001871 // CNNVD: CNNVD-201203-425 // NVD: CVE-2012-1462

REFERENCES

url:http://www.securityfocus.com/archive/1/522005

Trust: 1.7

url:http://www.ieee-security.org/tc/sp2012/program.html

Trust: 1.7

url:http://www.securityfocus.com/bid/52613

Trust: 1.1

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/74310

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2012-1462

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2012-1462

Trust: 0.8

url:http://www.nsfocus.net/vulndb/19217

Trust: 0.6

url:http://www.ahnlab.com

Trust: 0.3

url:http://www.avg.com

Trust: 0.3

url:http://www.emsisoft.com/en/software/antimalware/

Trust: 0.3

url:http://www.safenet-inc.com/data-protection/content-security-esafe/

Trust: 0.3

url:http://www.fortinet.com/

Trust: 0.3

url:http://www.ikarus.at

Trust: 0.3

url:http://global.jiangmin.com/

Trust: 0.3

url:http://www.kaspersky.com/

Trust: 0.3

url:http://anti-virus-software-review.toptenreviews.com/norman-review.html

Trust: 0.3

url:http://www.quickheal.com/

Trust: 0.3

url:http://www.sophos.com/

Trust: 0.3

url:http://www.symantec.com

Trust: 0.3

url:/archive/1/522005

Trust: 0.3

sources: VULHUB: VHN-54743 // BID: 52613 // JVNDB: JVNDB-2012-001871 // CNNVD: CNNVD-201203-425 // NVD: CVE-2012-1462

CREDITS

Suman Jana and Vitaly Shmatikov

Trust: 0.3

sources: BID: 52613

SOURCES

db:VULHUBid:VHN-54743
db:BIDid:52613
db:JVNDBid:JVNDB-2012-001871
db:CNNVDid:CNNVD-201203-425
db:NVDid:CVE-2012-1462

LAST UPDATE DATE

2024-11-23T21:46:23.665000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-54743date:2017-08-29T00:00:00
db:BIDid:52613date:2012-03-20T00:00:00
db:JVNDBid:JVNDB-2012-001871date:2012-03-23T00:00:00
db:CNNVDid:CNNVD-201203-425date:2012-03-26T00:00:00
db:NVDid:CVE-2012-1462date:2024-11-21T01:37:02.570

SOURCES RELEASE DATE

db:VULHUBid:VHN-54743date:2012-03-21T00:00:00
db:BIDid:52613date:2012-03-20T00:00:00
db:JVNDBid:JVNDB-2012-001871date:2012-03-23T00:00:00
db:CNNVDid:CNNVD-201203-425date:2012-03-26T00:00:00
db:NVDid:CVE-2012-1462date:2012-03-21T10:11:49.707