ID

VAR-201203-0380


CVE

CVE-2012-1456


TITLE

Multiple products TAR Vulnerability that prevents file parsers from detecting malware

Trust: 0.8

sources: JVNDB: JVNDB-2012-001900

DESCRIPTION

The TAR file parser in AVG Anti-Virus 10.0.0.1190, Quick Heal (aka Cat QuickHeal) 11.00, Comodo Antivirus 7424, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, F-Prot Antivirus 4.6.2.117, Fortinet Antivirus 4.2.254.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Jiangmin Antivirus 13.0.900, Kaspersky Anti-Virus 7.0.0.125, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwasher) 2010.1C, NOD32 Antivirus 5795, Norman Antivirus 6.06.12, Panda Antivirus 10.0.2.7, Rising Antivirus 22.83.00.03, Sophos Anti-Virus 4.61.0, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Trend Micro AntiVirus 9.120.0.1004, and Trend Micro HouseCall 9.120.0.1004 allows remote attackers to bypass malware detection via a TAR file with an appended ZIP file. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations. Multiple products TAR A file parser contains a vulnerability that can prevent malware detection. Different TAR If it is announced that there is also a problem with the parser implementation, this vulnerability can be CVE May be split.By a third party ZIP File attached TAR Malware detection may be avoided via files. Successful exploits will allow attackers to bypass on-demand virus scanning, possibly allowing malicious files to escape detection. The following products are affected: AVG AVG Anti-Virus 10.0.0.1190 Quick Heal Technologies CAT-QuickHeal 11.00 Comodo AntiVirus 7424 Emsisoft Antivirus 5.1.0.1 eSafe Antivirus 7.0.17.0 Frisk Software F-Prot Antivirus 4.6.2.117 Fortinet Antivirus 4.2.254.0 Ikarus Antivirus T3.1.1.97.0

Trust: 1.98

sources: NVD: CVE-2012-1456 // JVNDB: JVNDB-2012-001900 // BID: 52608 // VULHUB: VHN-54737

AFFECTED PRODUCTS

vendor:comodomodel:antivirusscope:eqversion:7424

Trust: 2.1

vendor:avgmodel:anti-virusscope:eqversion:10.0.0.1190

Trust: 1.8

vendor:emsisoftmodel:anti-malwarescope:eqversion:5.1.0.1

Trust: 1.8

vendor:ikarusmodel:virus utilities t3 command line scannerscope:eqversion:1.1.97.0

Trust: 1.8

vendor:jiangminmodel:antivirusscope:eqversion:13.0.900

Trust: 1.8

vendor:aladdinmodel:esafescope:eqversion:7.0.17.0

Trust: 1.8

vendor:kasperskymodel:anti-virusscope:eqversion:7.0.0.125

Trust: 1.8

vendor:sophosmodel:anti-virusscope:eqversion:4.61.0

Trust: 1.8

vendor:fortinetmodel:antivirusscope:eqversion:4.2.254.0

Trust: 1.8

vendor:mcafeemodel:scan enginescope:eqversion:5.400.0.1158

Trust: 1.8

vendor:trendmicromodel:trend micro antivirusscope:eqversion:9.120.0.1004

Trust: 1.6

vendor:trendmicromodel:housecallscope:eqversion:9.120.0.1004

Trust: 1.6

vendor:rising globalmodel:antivirusscope:eqversion:22.83.00.03

Trust: 1.0

vendor:esetmodel:nod32 antivirusscope:eqversion:5795

Trust: 1.0

vendor:symantecmodel:endpoint protectionscope:eqversion:11.0

Trust: 1.0

vendor:pandasecuritymodel:panda antivirusscope:eqversion:10.0.2.7

Trust: 1.0

vendor:mcafeemodel:gatewayscope:eqversion:2010.1c

Trust: 1.0

vendor:normanmodel:antivirus \& antispywarescope:eqversion:6.06.12

Trust: 1.0

vendor:catmodel:quick healscope:eqversion:11.00

Trust: 1.0

vendor:f protmodel:f-prot antivirusscope:eqversion:4.6.2.117

Trust: 1.0

vendor:risingmodel:antivirusscope:eqversion:22.83.00.03

Trust: 0.8

vendor:esetmodel:nod32 anti-virusscope:eqversion:5795

Trust: 0.8

vendor:friskmodel:f-prot antivirusscope:eqversion:4.6.2.117

Trust: 0.8

vendor:normanmodel:antivirusscope:eqversion:6.06.12

Trust: 0.8

vendor:panda securitymodel:antivirusscope:eqversion:10.0.2.7

Trust: 0.8

vendor:quick heal k kmodel:healscope:eqversion:11.00

Trust: 0.8

vendor:symantecmodel:endpoint protectionscope:eqversion:11

Trust: 0.8

vendor:trend micromodel:antivirusscope:eqversion:9.120.0.1004

Trust: 0.8

vendor:trend micromodel:housecallscope:eqversion:9.120.0.1004

Trust: 0.8

vendor:mcafeemodel:web gateway softwarescope:eqversion:2010.1c

Trust: 0.8

vendor:quick healmodel:cat-quickhealscope:eqversion:11.00

Trust: 0.3

vendor:ikarusmodel:antivirus t3.1.1.97.0scope: - version: -

Trust: 0.3

vendor:friskmodel:software f-prot antivirusscope:eqversion:4.6.2117

Trust: 0.3

vendor:fortinetmodel:antivirusscope:eqversion:4.2.2540

Trust: 0.3

vendor:esafemodel:antivirusscope:eqversion:7.0.170

Trust: 0.3

vendor:emsisoftmodel:antivirusscope:eqversion:5.11

Trust: 0.3

vendor:avgmodel:anti-virusscope:eqversion:10.01190

Trust: 0.3

sources: BID: 52608 // JVNDB: JVNDB-2012-001900 // CNNVD: CNNVD-201203-419 // NVD: CVE-2012-1456

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2012-1456
value: MEDIUM

Trust: 1.0

NVD: CVE-2012-1456
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-201203-419
value: MEDIUM

Trust: 0.6

VULHUB: VHN-54737
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2012-1456
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-54737
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-54737 // JVNDB: JVNDB-2012-001900 // CNNVD: CNNVD-201203-419 // NVD: CVE-2012-1456

PROBLEMTYPE DATA

problemtype:CWE-264

Trust: 1.9

sources: VULHUB: VHN-54737 // JVNDB: JVNDB-2012-001900 // NVD: CVE-2012-1456

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201203-419

TYPE

permissions and access control

Trust: 0.6

sources: CNNVD: CNNVD-201203-419

CONFIGURATIONS

sources: JVNDB: JVNDB-2012-001900

PATCH

title:AVG Anti-Virusurl:http://www.avgjapan.com/home-small-office-security/buy-antivirus

Trust: 0.8

title:Rising Antivirusurl:http://www.rising-global.com/

Trust: 0.8

title:Comodo Antivirusurl:http://www.comodo.com/home/internet-security/antivirus.php

Trust: 0.8

title:Emsisoft Anti-Malwareurl:http://www.emsisoft.com/en/software/antimalware/

Trust: 0.8

title:ESET NOD32アンチウイルスurl:http://www.eset.com/us/

Trust: 0.8

title:Fortinet Antivirusurl:http://www.fortinet.com/solutions/antivirus.html

Trust: 0.8

title:F-Prot Antivirusurl:http://www.f-prot.com/index.html

Trust: 0.8

title:Top Pageurl:http://www.ikarus.at/en/

Trust: 0.8

title:Jiangmin Antivirusurl:http://global.jiangmin.com/

Trust: 0.8

title:McAfee Scan Engineurl:http://www.mcafee.com/us/support/support-eol-scan-engine.aspx

Trust: 0.8

title:McAfee Web Gatewayurl:http://www.mcafee.com/us/products/web-gateway.aspx

Trust: 0.8

title:Norman Antivirusurl:http://www.norman.com/products/antivirus_antispyware/en

Trust: 0.8

title:Panda Antivirusurl:http://www.ps-japan.co.jp/

Trust: 0.8

title:Quick Healurl:http://www.quickheal.com/

Trust: 0.8

title:Sophos Anti-Virusurl:http://www.sophos.com/ja-jp/

Trust: 0.8

title:Endpoint Protectionurl:http://www.symantec.com/ja/jp/endpoint-protection

Trust: 0.8

title:Top Pageurl:http://jp.trendmicro.com/jp/home/index.html

Trust: 0.8

title:Trend Micro HouseCallurl:http://housecall.trendmicro.com/

Trust: 0.8

title:eSafeurl:http://www.aladdin.co.jp/esafe/

Trust: 0.8

title:Kaspersky Anti-Virusurl:http://www.kaspersky.com/kaspersky_anti-virus

Trust: 0.8

sources: JVNDB: JVNDB-2012-001900

EXTERNAL IDS

db:NVDid:CVE-2012-1456

Trust: 2.8

db:BIDid:52608

Trust: 1.4

db:OSVDBid:80396

Trust: 1.1

db:OSVDBid:80389

Trust: 1.1

db:OSVDBid:80391

Trust: 1.1

db:OSVDBid:80403

Trust: 1.1

db:OSVDBid:80395

Trust: 1.1

db:OSVDBid:80390

Trust: 1.1

db:OSVDBid:80406

Trust: 1.1

db:OSVDBid:80409

Trust: 1.1

db:JVNDBid:JVNDB-2012-001900

Trust: 0.8

db:CNNVDid:CNNVD-201203-419

Trust: 0.7

db:NSFOCUSid:19212

Trust: 0.6

db:BUGTRAQid:20120319 EVASION ATTACKS EXPOLITING FILE-PARSING VULNERABILITIES IN ANTIVIRUS PRODUCTS

Trust: 0.6

db:VULHUBid:VHN-54737

Trust: 0.1

sources: VULHUB: VHN-54737 // BID: 52608 // JVNDB: JVNDB-2012-001900 // CNNVD: CNNVD-201203-419 // NVD: CVE-2012-1456

REFERENCES

url:http://www.securityfocus.com/archive/1/522005

Trust: 1.7

url:http://www.ieee-security.org/tc/sp2012/program.html

Trust: 1.7

url:http://www.securityfocus.com/bid/52608

Trust: 1.1

url:http://osvdb.org/80389

Trust: 1.1

url:http://osvdb.org/80390

Trust: 1.1

url:http://osvdb.org/80391

Trust: 1.1

url:http://osvdb.org/80395

Trust: 1.1

url:http://osvdb.org/80396

Trust: 1.1

url:http://osvdb.org/80403

Trust: 1.1

url:http://osvdb.org/80406

Trust: 1.1

url:http://osvdb.org/80409

Trust: 1.1

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/74289

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2012-1456

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2012-1456

Trust: 0.8

url:http://www.nsfocus.net/vulndb/19212

Trust: 0.6

url:http://www.avg.com

Trust: 0.3

url:http://www.comodo.com/

Trust: 0.3

url:http://www.emsisoft.com/en/software/antimalware/

Trust: 0.3

url:http://www.safenet-inc.com/data-protection/content-security-esafe/

Trust: 0.3

url:http://www.fortinet.com/

Trust: 0.3

url:http://www.f-prot.com/

Trust: 0.3

url:http://www.ikarus.at

Trust: 0.3

url:http://www.quickheal.com/

Trust: 0.3

url:/archive/1/522005

Trust: 0.3

sources: VULHUB: VHN-54737 // BID: 52608 // JVNDB: JVNDB-2012-001900 // CNNVD: CNNVD-201203-419 // NVD: CVE-2012-1456

CREDITS

Suman Jana and Vitaly Shmatikov

Trust: 0.3

sources: BID: 52608

SOURCES

db:VULHUBid:VHN-54737
db:BIDid:52608
db:JVNDBid:JVNDB-2012-001900
db:CNNVDid:CNNVD-201203-419
db:NVDid:CVE-2012-1456

LAST UPDATE DATE

2024-11-23T21:46:23.269000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-54737date:2017-08-29T00:00:00
db:BIDid:52608date:2012-03-20T00:00:00
db:JVNDBid:JVNDB-2012-001900date:2012-03-26T00:00:00
db:CNNVDid:CNNVD-201203-419date:2012-04-01T00:00:00
db:NVDid:CVE-2012-1456date:2024-11-21T01:37:01.597

SOURCES RELEASE DATE

db:VULHUBid:VHN-54737date:2012-03-21T00:00:00
db:BIDid:52608date:2012-03-20T00:00:00
db:JVNDBid:JVNDB-2012-001900date:2012-03-26T00:00:00
db:CNNVDid:CNNVD-201203-419date:2012-03-26T00:00:00
db:NVDid:CVE-2012-1456date:2012-03-21T10:11:49.240