MidnightBSD

Advisories for aladdin

CVE-2009-2631 MEDIUM

Multiple clientless SSL VPN products that run in web browsers, including Stonesoft StoneGate; Cisco ASA; SonicWALL E-Class SSL VPN and SonicWALL SSL VPN; SafeNet SecureWire Access Gateway; Juniper Networks Secure Access; Nortel CallPilot; Citrix Access Gateway; and other products, when running in configurations that do not restrict access to the same domain as the VPN, retrieve the content of remote URLs from one domain and rewrite them so they originate from the VPN's domain, which violates the same origin policy and allows remote attackers to conduct cross-site scripting attacks, read cookies that originated from other domains, access the Web VPN session to gain access to internal resources, perform key logging, and conduct other attacks. NOTE: it could be argued that this is a fundamental design problem in any clientless VPN solution, as opposed to a commonly-introduced error that can be fixed in separate implementations. Therefore a single CVE has been assigned for all products that have this design

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-284,CWE-264,

Products Affected

Vendor Product Version
sonicwall e-class_ssl_vpn *
sonicwall ssl_vpn *
stonesoft stonegate *
cisco adaptive_security_appliance *
aladdin safenet_securewire_access_gateway *
CVE-2012-1429 MEDIUM

The ELF file parser in Bitdefender 7.2, Comodo Antivirus 7424, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, F-Secure Anti-Virus 9.0.16160.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwasher) 2010.1C, and nProtect Anti-Virus 2011-01-17.01 allows remote attackers to bypass malware detection via an ELF file with a ustar character sequence at a certain location. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different ELF parser implementations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
softwin bitdefender 7.2
comodo comodo_antivirus 7424
emsisoft anti-malware 5.1.0.1
mcafee gateway 2010.1c
f-secure f-secure_anti-virus 9.0.16160.0
aladdin esafe 7.0.17.0
ikarus ikarus_virus_utilities_t3_command_line_scanner 1.1.97.0
nprotect nprotect_antivirus 2011-01-17.01
mcafee scan_engine 5.400.0.1158
CVE-2012-1430 MEDIUM

The ELF file parser in Bitdefender 7.2, Comodo Antivirus 7424, eSafe 7.0.17.0, F-Secure Anti-Virus 9.0.16160.0, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwasher) 2010.1C, nProtect Anti-Virus 2011-01-17.01, Sophos Anti-Virus 4.61.0, and Rising Antivirus 22.83.00.03 allows remote attackers to bypass malware detection via an ELF file with a \19\04\00\10 character sequence at a certain location. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different ELF parser implementations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
comodo comodo_antivirus 7424
bitdefender bitdefender 7.2
mcafee gateway 2010.1c
aladdin esafe 7.0.17.0
f-secure anti-virus 9.0.16160.0
rising-global rising_antivirus 22.83.00.03
nprotect nprotect_antivirus 2011-01-17.01
sophos sophos_anti-virus 4.61.0
mcafee scan_engine 5.400.0.1158
CVE-2012-1431 MEDIUM

The ELF file parser in Bitdefender 7.2, Command Antivirus 5.2.11.5, Comodo Antivirus 7424, eSafe 7.0.17.0, F-Prot Antivirus 4.6.2.117, F-Secure Anti-Virus 9.0.16160.0, McAfee Gateway (formerly Webwasher) 2010.1C, nProtect Anti-Virus 2011-01-17.01, Sophos Anti-Virus 4.61.0, and Rising Antivirus 22.83.00.03 allows remote attackers to bypass malware detection via an ELF file with a \4a\46\49\46 character sequence at a certain location. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different ELF parser implementations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
comodo comodo_antivirus 7424
bitdefender bitdefender 7.2
authentium command_antivirus 5.2.11.5
mcafee gateway 2010.1c
f-secure f-secure_anti-virus 9.0.16160.0
aladdin esafe 7.0.17.0
rising-global rising_antivirus 22.83.00.03
f-prot f-prot_antivirus 4.6.2.117
nprotect nprotect_antivirus 2011-01-17.01
sophos sophos_anti-virus 4.61.0
CVE-2012-1432 MEDIUM

The Microsoft EXE file parser in Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an EXE file with a \57\69\6E\5A\69\70 character sequence at a certain location. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different EXE parser implementations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
emsisoft anti-malware 5.1.0.1
pandasecurity panda_antivirus 10.0.2.7
aladdin esafe 7.0.17.0
ikarus ikarus_virus_utilities_t3_command_line_scanner 1.1.97.0
CVE-2012-1433 MEDIUM

The Microsoft EXE file parser in AhnLab V3 Internet Security 2011.01.18.00, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an EXE file with a \4a\46\49\46 character sequence at a certain location. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different EXE parser implementations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ahnlab v3_internet_security 2011.01.18.00
emsisoft anti-malware 5.1.0.1
pandasecurity panda_antivirus 10.0.2.7
aladdin esafe 7.0.17.0
ikarus ikarus_virus_utilities_t3_command_line_scanner 1.1.97.0
CVE-2012-1435 MEDIUM

The Microsoft EXE file parser in AhnLab V3 Internet Security 2011.01.18.00, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an EXE file with a \50\4B\4C\49\54\45 character sequence at a certain location. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different EXE parser implementations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ahnlab v3_internet_security 2011.01.18.00
emsisoft anti-malware 5.1.0.1
pandasecurity panda_antivirus 10.0.2.7
aladdin esafe 7.0.17.0
ikarus ikarus_virus_utilities_t3_command_line_scanner 1.1.97.0
CVE-2012-1436 MEDIUM

The Microsoft EXE file parser in AhnLab V3 Internet Security 2011.01.18.00, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an EXE file with a \2D\6C\68 character sequence at a certain location. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different EXE parser implementations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ahnlab v3_internet_security 2011.01.18.00
emsisoft anti-malware 5.1.0.1
pandasecurity panda_antivirus 10.0.2.7
aladdin esafe 7.0.17.0
ikarus ikarus_virus_utilities_t3_command_line_scanner 1.1.97.0
CVE-2012-1439 MEDIUM

The ELF file parser in eSafe 7.0.17.0, Rising Antivirus 22.83.00.03, Fortinet Antivirus 4.2.254.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an ELF file with a modified padding field. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different ELF parser implementations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
pandasecurity panda_antivirus 10.0.2.7
aladdin esafe 7.0.17.0
rising-global rising_antivirus 22.83.00.03
fortinet fortinet_antivirus 4.2.254.0
CVE-2012-1440 MEDIUM

The ELF file parser in Norman Antivirus 6.06.12, eSafe 7.0.17.0, CA eTrust Vet Antivirus 36.1.8511, Fortinet Antivirus 4.2.254.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an ELF file with a modified identsize field. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different ELF parser implementations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ca etrust_vet_antivirus 36.1.8511
pandasecurity panda_antivirus 10.0.2.7
aladdin esafe 7.0.17.0
norman norman_antivirus_&_antispyware 6.06.12
fortinet fortinet_antivirus 4.2.254.0
CVE-2012-1441 MEDIUM

The Microsoft EXE file parser in eSafe 7.0.17.0 and Prevx 3.0 allows remote attackers to bypass malware detection via an EXE file with a modified value in any of several e_ fields. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different EXE parser implementations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
aladdin esafe 7.0.17.0
prevx prevx 3.0
CVE-2012-1442 MEDIUM

The ELF file parser in Quick Heal (aka Cat QuickHeal) 11.00, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwasher) 2010.1C, eSafe 7.0.17.0, Kaspersky Anti-Virus 7.0.0.125, F-Secure Anti-Virus 9.0.16160.0, Sophos Anti-Virus 4.61.0, Antiy Labs AVL SDK 2.0.3.7, Rising Antivirus 22.83.00.03, Fortinet Antivirus 4.2.254.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an ELF file with a modified class field. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different ELF parser implementations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
kaspersky kaspersky_anti-virus 7.0.0.125
antiy avl_sdk 2.0.3.7
mcafee gateway 2010.1c
pandasecurity panda_antivirus 10.0.2.7
f-secure f-secure_anti-virus 9.0.16160.0
aladdin esafe 7.0.17.0
rising-global rising_antivirus 22.83.00.03
cat quick_heal 11.00
sophos sophos_anti-virus 4.61.0
fortinet fortinet_antivirus 4.2.254.0
mcafee scan_engine 5.400.0.1158
CVE-2012-1443 MEDIUM

The RAR file parser in ClamAV 0.96.4, Rising Antivirus 22.83.00.03, Quick Heal (aka Cat QuickHeal) 11.00, G Data AntiVirus 21, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Command Antivirus 5.2.11.5, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Emsisoft Anti-Malware 5.1.0.1, PC Tools AntiVirus 7.0.3.5, F-Prot Antivirus 4.6.2.117, VirusBuster 13.6.151.0, Fortinet Antivirus 4.2.254.0, Antiy Labs AVL SDK 2.0.3.7, K7 AntiVirus 9.77.3565, Trend Micro HouseCall 9.120.0.1004, Kaspersky Anti-Virus 7.0.0.125, Jiangmin Antivirus 13.0.900, Antimalware Engine 1.1.6402.0 in Microsoft Security Essentials 2.0, Sophos Anti-Virus 4.61.0, NOD32 Antivirus 5795, Avira AntiVir 7.11.1.163, Norman Antivirus 6.06.12, McAfee Anti-Virus Scanning Engine 5.400.0.1158, Panda Antivirus 10.0.2.7, McAfee Gateway (formerly Webwasher) 2010.1C, Trend Micro AntiVirus 9.120.0.1004, Comodo Antivirus 7424, Bitdefender 7.2, eSafe 7.0.17.0, F-Secure Anti-Virus 9.0.16160.0, nProtect Anti-Virus 2011-01-17.01, AhnLab V3 Internet Security 2011.01.18.00, AVG Anti-Virus 10.0.0.1190, avast! Antivirus 4.8.1351.0 and 5.0.677.0, and VBA32 3.12.14.2 allows user-assisted remote attackers to bypass malware detection via a RAR file with an initial MZ character sequence. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different RAR parser implementations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
pc_tools pc_tools_antivirus 7.0.3.5
jiangmin jiangmin_antivirus 13.0.900
comodo comodo_antivirus 7424
eset nod32_antivirus 5795
antiy avl_sdk 2.0.3.7
aladdin esafe 7.0.17.0
cat quick_heal 11.00
trendmicro housecall 9.120.0.1004
alwil avast_antivirus 5.0.677.0
mcafee scan_engine 5.400.0.1158
bitdefender bitdefender 7.2
alwil avast_antivirus 4.8.1351.0
authentium command_antivirus 5.2.11.5
mcafee gateway 2010.1c
f-secure f-secure_anti-virus 9.0.16160.0
rising-global rising_antivirus 22.83.00.03
avira antivir 7.11.1.163
microsoft security_essentials 2.0
emsisoft anti-malware 5.1.0.1
symantec endpoint_protection 11.0
ikarus ikarus_virus_utilities_t3_command_line_scanner 1.1.97.0
nprotect nprotect_antivirus 2011-01-17.01
anti-virus vba32 3.12.14.2
sophos sophos_anti-virus 4.61.0
clamav clamav 0.96.4
fortinet fortinet_antivirus 4.2.254.0
virusbuster virusbuster 13.6.151.0
ahnlab v3_internet_security 2011.01.18.00
kaspersky kaspersky_anti-virus 7.0.0.125
trendmicro trend_micro_antivirus 9.120.0.1004
pandasecurity panda_antivirus 10.0.2.7
f-prot f-prot_antivirus 4.6.2.117
gdata-software g_data_antivirus 21
norman norman_antivirus_&_antispyware 6.06.12
avg avg_anti-virus 10.0.0.1190
k7computing antivirus 9.77.3565
CVE-2012-1444 MEDIUM

The ELF file parser in eSafe 7.0.17.0, Prevx 3.0, Fortinet Antivirus 4.2.254.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an ELF file with a modified abiversion field. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different ELF parser implementations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
pandasecurity panda_antivirus 10.0.2.7
aladdin esafe 7.0.17.0
prevx prevx 3.0
fortinet fortinet_antivirus 4.2.254.0
CVE-2012-1445 MEDIUM

The ELF file parser in eSafe 7.0.17.0, Rising Antivirus 22.83.00.03, Fortinet Antivirus 4.2.254.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an ELF file with a modified abi field. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different ELF parser implementations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
pandasecurity panda_antivirus 10.0.2.7
aladdin esafe 7.0.17.0
rising-global rising_antivirus 22.83.00.03
fortinet fortinet_antivirus 4.2.254.0
CVE-2012-1446 MEDIUM

The ELF file parser in Quick Heal (aka Cat QuickHeal) 11.00, McAfee Anti-Virus Scanning Engine 5.400.0.1158, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Norman Antivirus 6.06.12, eSafe 7.0.17.0, Kaspersky Anti-Virus 7.0.0.125, McAfee Gateway (formerly Webwasher) 2010.1C, Sophos Anti-Virus 4.61.0, CA eTrust Vet Antivirus 36.1.8511, Antiy Labs AVL SDK 2.0.3.7, PC Tools AntiVirus 7.0.3.5, Rising Antivirus 22.83.00.03, Fortinet Antivirus 4.2.254.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an ELF file with a modified encoding field. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different ELF parser implementations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
pc_tools pc_tools_antivirus 7.0.3.5
antiy avl_sdk 2.0.3.7
aladdin esafe 7.0.17.0
symantec endpoint_protection 11.0
cat quick_heal 11.00
sophos sophos_anti-virus 4.61.0
fortinet fortinet_antivirus 4.2.254.0
mcafee scan_engine 5.400.0.1158
ca etrust_vet_antivirus 36.1.8511
kaspersky kaspersky_anti-virus 7.0.0.125
mcafee gateway 2010.1c
pandasecurity panda_antivirus 10.0.2.7
rising-global rising_antivirus 22.83.00.03
norman norman_antivirus_&_antispyware 6.06.12
CVE-2012-1447 MEDIUM

The ELF file parser in Fortinet Antivirus 4.2.254.0, eSafe 7.0.17.0, Dr.Web 5.0.2.03300, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an ELF file with a modified e_version field. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different ELF parser implementations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
pandasecurity panda_antivirus 10.0.2.7
drweb dr.web_antivirus 5.0.2.03300
aladdin esafe 7.0.17.0
fortinet fortinet_antivirus 4.2.254.0
CVE-2012-1454 MEDIUM

The ELF file parser in Dr.Web 5.0.2.03300, eSafe 7.0.17.0, McAfee Gateway (formerly Webwasher) 2010.1C, Rising Antivirus 22.83.00.03, Fortinet Antivirus 4.2.254.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an ELF file with a modified ei_version field. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different ELF parser implementations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
mcafee gateway 2010.1c
pandasecurity panda_antivirus 10.0.2.7
drweb dr.web_antivirus 5.0.2.03300
aladdin esafe 7.0.17.0
rising-global rising_antivirus 22.83.00.03
fortinet fortinet_antivirus 4.2.254.0
CVE-2012-1456 MEDIUM

The TAR file parser in AVG Anti-Virus 10.0.0.1190, Quick Heal (aka Cat QuickHeal) 11.00, Comodo Antivirus 7424, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, F-Prot Antivirus 4.6.2.117, Fortinet Antivirus 4.2.254.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Jiangmin Antivirus 13.0.900, Kaspersky Anti-Virus 7.0.0.125, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwasher) 2010.1C, NOD32 Antivirus 5795, Norman Antivirus 6.06.12, Panda Antivirus 10.0.2.7, Rising Antivirus 22.83.00.03, Sophos Anti-Virus 4.61.0, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Trend Micro AntiVirus 9.120.0.1004, and Trend Micro HouseCall 9.120.0.1004 allows remote attackers to bypass malware detection via a TAR file with an appended ZIP file. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
jiangmin jiangmin_antivirus 13.0.900
comodo comodo_antivirus 7424
emsisoft anti-malware 5.1.0.1
eset nod32_antivirus 5795
aladdin esafe 7.0.17.0
symantec endpoint_protection 11.0
cat quick_heal 11.00
ikarus ikarus_virus_utilities_t3_command_line_scanner 1.1.97.0
sophos sophos_anti-virus 4.61.0
trendmicro housecall 9.120.0.1004
fortinet fortinet_antivirus 4.2.254.0
mcafee scan_engine 5.400.0.1158
kaspersky kaspersky_anti-virus 7.0.0.125
trendmicro trend_micro_antivirus 9.120.0.1004
mcafee gateway 2010.1c
pandasecurity panda_antivirus 10.0.2.7
rising-global rising_antivirus 22.83.00.03
f-prot f-prot_antivirus 4.6.2.117
norman norman_antivirus_&_antispyware 6.06.12
avg avg_anti-virus 10.0.0.1190
CVE-2012-1457 MEDIUM

The TAR file parser in Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8.1351.0 and 5.0.677.0, AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Quick Heal (aka Cat QuickHeal) 11.00, ClamAV 0.96.4, Command Antivirus 5.2.11.5, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, F-Prot Antivirus 4.6.2.117, G Data AntiVirus 21, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Jiangmin Antivirus 13.0.900, K7 AntiVirus 9.77.3565, Kaspersky Anti-Virus 7.0.0.125, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwasher) 2010.1C, Antimalware Engine 1.1.6402.0 in Microsoft Security Essentials 2.0, NOD32 Antivirus 5795, Norman Antivirus 6.06.12, PC Tools AntiVirus 7.0.3.5, Rising Antivirus 22.83.00.03, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Trend Micro AntiVirus 9.120.0.1004, Trend Micro HouseCall 9.120.0.1004, VBA32 3.12.14.2, and VirusBuster 13.6.151.0 allows remote attackers to bypass malware detection via a TAR archive entry with a length field that exceeds the total TAR file size. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
pc_tools pc_tools_antivirus 7.0.3.5
jiangmin jiangmin_antivirus 13.0.900
eset nod32_antivirus 5795
antiy avl_sdk 2.0.3.7
aladdin esafe 7.0.17.0
cat quick_heal 11.00
trendmicro housecall 9.120.0.1004
alwil avast_antivirus 5.0.677.0
mcafee scan_engine 5.400.0.1158
bitdefender bitdefender 7.2
alwil avast_antivirus 4.8.1351.0
authentium command_antivirus 5.2.11.5
mcafee gateway 2010.1c
rising-global rising_antivirus 22.83.00.03
avira antivir 7.11.1.163
microsoft security_essentials 2.0
emsisoft anti-malware 5.1.0.1
symantec endpoint_protection 11.0
ikarus ikarus_virus_utilities_t3_command_line_scanner 1.1.97.0
anti-virus vba32 3.12.14.2
clamav clamav 0.96.4
virusbuster virusbuster 13.6.151.0
kaspersky kaspersky_anti-virus 7.0.0.125
trendmicro trend_micro_antivirus 9.120.0.1004
f-prot f-prot_antivirus 4.6.2.117
gdata-software g_data_antivirus 21
norman norman_antivirus_&_antispyware 6.06.12
avg avg_anti-virus 10.0.0.1190
k7computing antivirus 9.77.3565
CVE-2012-1460 MEDIUM

The Gzip file parser in Antiy Labs AVL SDK 2.0.3.7, Quick Heal (aka Cat QuickHeal) 11.00, Command Antivirus 5.2.11.5, eSafe 7.0.17.0, F-Prot Antivirus 4.6.2.117, Jiangmin Antivirus 13.0.900, K7 AntiVirus 9.77.3565, and VBA32 3.12.14.2 allows remote attackers to bypass malware detection via a .tar.gz file with stray bytes at the end. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different Gzip parser implementations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
jiangmin jiangmin_antivirus 13.0.900
authentium command_antivirus 5.2.11.5
antiy avl_sdk 2.0.3.7
aladdin esafe 7.0.17.0
cat quick_heal 11.00
f-prot f-prot_antivirus 4.6.2.117
anti-virus vba32 3.12.14.2
k7computing antivirus 9.77.3565
CVE-2012-1462 MEDIUM

The ZIP file parser in AhnLab V3 Internet Security 2011.01.18.00, AVG Anti-Virus 10.0.0.1190, Quick Heal (aka Cat QuickHeal) 11.00, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, Fortinet Antivirus 4.2.254.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Jiangmin Antivirus 13.0.900, Kaspersky Anti-Virus 7.0.0.125, Norman Antivirus 6.06.12, Sophos Anti-Virus 4.61.0, and AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11 allows remote attackers to bypass malware detection via a ZIP file containing an invalid block of data at the beginning. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different ZIP parser implementations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
jiangmin jiangmin_antivirus 13.0.900
ahnlab v3_internet_security 2011.01.18.00
kaspersky kaspersky_anti-virus 7.0.0.125
emsisoft anti-malware 5.1.0.1
aladdin esafe 7.0.17.0
symantec endpoint_protection 11.0
cat quick_heal 11.00
ikarus ikarus_virus_utilities_t3_command_line_scanner 1.1.97.0
avg avg_anti-virus 10.0.0.1190
fortinet fortinet_antivirus 4.2.254.0
CVE-2012-1463 MEDIUM

The ELF file parser in AhnLab V3 Internet Security 2011.01.18.00, Bitdefender 7.2, Quick Heal (aka Cat QuickHeal) 11.00, Command Antivirus 5.2.11.5, Comodo Antivirus 7424, eSafe 7.0.17.0, F-Prot Antivirus 4.6.2.117, F-Secure Anti-Virus 9.0.16160.0, McAfee Anti-Virus Scanning Engine 5.400.0.1158, Norman Antivirus 6.06.12, nProtect Anti-Virus 2011-01-17.01, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an ELF file with a modified endianness field. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different ELF parser implementations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
comodo comodo_antivirus 7424
aladdin esafe 7.0.17.0
cat quick_heal 11.00
nprotect nprotect_antivirus 2011-01-17.01
mcafee scan_engine 5.400.0.1158
ahnlab v3_internet_security 2011.01.18.00
bitdefender bitdefender 7.2
authentium command_antivirus 5.2.11.5
pandasecurity panda_antivirus 10.0.2.7
f-secure f-secure_anti-virus 9.0.16160.0
f-prot f-prot_antivirus 4.6.2.117
norman norman_antivirus_&_antispyware 6.06.12