MidnightBSD

Advisories for antiy

CVE-2012-1424 MEDIUM

The TAR file parser in Antiy Labs AVL SDK 2.0.3.7, Quick Heal (aka Cat QuickHeal) 11.00, Jiangmin Antivirus 13.0.900, Norman Antivirus 6.06.12, PC Tools AntiVirus 7.0.3.5, and Sophos Anti-Virus 4.61.0 allows remote attackers to bypass malware detection via a POSIX TAR file with a \19\04\00\10 character sequence at a certain location. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
jiangmin jiangmin_antivirus 13.0.900
antiy avl_sdk 2.0.3.7
norman norman_antivirus_&_antispyware 6.06.12
cat quick_heal 11.00
sophos sophos_anti-virus 4.61.0
pc_tools pc_tools_antivirus 7.0.3.5
CVE-2012-1425 MEDIUM

The TAR file parser in Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, Quick Heal (aka Cat QuickHeal) 11.00, Emsisoft Anti-Malware 5.1.0.1, Fortinet Antivirus 4.2.254.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Jiangmin Antivirus 13.0.900, Kaspersky Anti-Virus 7.0.0.125, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwasher) 2010.1C, NOD32 Antivirus 5795, Norman Antivirus 6.06.12, PC Tools AntiVirus 7.0.3.5, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Trend Micro AntiVirus 9.120.0.1004, and Trend Micro HouseCall 9.120.0.1004 allows remote attackers to bypass malware detection via a POSIX TAR file with an initial \50\4B\03\04 character sequence. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
mcafee gateway 2010.1c
symantec endpoint_protection 11.0
trendmicro housecall 9.120.0.1004
emsisoft anti-malware 5.1.0.1
mcafee scan_engine 5.400.0.1158
eset nod32_antivirus 5795
norman norman_antivirus_&_antispyware 6.06.12
ikarus ikarus_virus_utilities_t3_command_line_scanner 1.1.97.0
pc_tools pc_tools_antivirus 7.0.3.5
trendmicro trend_micro_antivirus 9.120.0.1004
kaspersky kaspersky_anti-virus 7.0.0.125
fortinet fortinet_antivirus 4.2.254.0
jiangmin jiangmin_antivirus 13.0.900
antiy avl_sdk 2.0.3.7
avira antivir 7.11.1.163
cat quick_heal 11.00
CVE-2012-1442 MEDIUM

The ELF file parser in Quick Heal (aka Cat QuickHeal) 11.00, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwasher) 2010.1C, eSafe 7.0.17.0, Kaspersky Anti-Virus 7.0.0.125, F-Secure Anti-Virus 9.0.16160.0, Sophos Anti-Virus 4.61.0, Antiy Labs AVL SDK 2.0.3.7, Rising Antivirus 22.83.00.03, Fortinet Antivirus 4.2.254.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an ELF file with a modified class field. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different ELF parser implementations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
mcafee gateway 2010.1c
kaspersky kaspersky_anti-virus 7.0.0.125
fortinet fortinet_antivirus 4.2.254.0
mcafee scan_engine 5.400.0.1158
antiy avl_sdk 2.0.3.7
sophos sophos_anti-virus 4.61.0
cat quick_heal 11.00
f-secure f-secure_anti-virus 9.0.16160.0
pandasecurity panda_antivirus 10.0.2.7
rising-global rising_antivirus 22.83.00.03
aladdin esafe 7.0.17.0
CVE-2012-1443 MEDIUM

The RAR file parser in ClamAV 0.96.4, Rising Antivirus 22.83.00.03, Quick Heal (aka Cat QuickHeal) 11.00, G Data AntiVirus 21, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Command Antivirus 5.2.11.5, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Emsisoft Anti-Malware 5.1.0.1, PC Tools AntiVirus 7.0.3.5, F-Prot Antivirus 4.6.2.117, VirusBuster 13.6.151.0, Fortinet Antivirus 4.2.254.0, Antiy Labs AVL SDK 2.0.3.7, K7 AntiVirus 9.77.3565, Trend Micro HouseCall 9.120.0.1004, Kaspersky Anti-Virus 7.0.0.125, Jiangmin Antivirus 13.0.900, Antimalware Engine 1.1.6402.0 in Microsoft Security Essentials 2.0, Sophos Anti-Virus 4.61.0, NOD32 Antivirus 5795, Avira AntiVir 7.11.1.163, Norman Antivirus 6.06.12, McAfee Anti-Virus Scanning Engine 5.400.0.1158, Panda Antivirus 10.0.2.7, McAfee Gateway (formerly Webwasher) 2010.1C, Trend Micro AntiVirus 9.120.0.1004, Comodo Antivirus 7424, Bitdefender 7.2, eSafe 7.0.17.0, F-Secure Anti-Virus 9.0.16160.0, nProtect Anti-Virus 2011-01-17.01, AhnLab V3 Internet Security 2011.01.18.00, AVG Anti-Virus 10.0.0.1190, avast! Antivirus 4.8.1351.0 and 5.0.677.0, and VBA32 3.12.14.2 allows user-assisted remote attackers to bypass malware detection via a RAR file with an initial MZ character sequence. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different RAR parser implementations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
symantec endpoint_protection 11.0
virusbuster virusbuster 13.6.151.0
microsoft security_essentials 2.0
trendmicro housecall 9.120.0.1004
eset nod32_antivirus 5795
f-secure f-secure_anti-virus 9.0.16160.0
norman norman_antivirus_&_antispyware 6.06.12
rising-global rising_antivirus 22.83.00.03
trendmicro trend_micro_antivirus 9.120.0.1004
nprotect nprotect_antivirus 2011-01-17.01
authentium command_antivirus 5.2.11.5
jiangmin jiangmin_antivirus 13.0.900
f-prot f-prot_antivirus 4.6.2.117
avg avg_anti-virus 10.0.0.1190
antiy avl_sdk 2.0.3.7
comodo comodo_antivirus 7424
sophos sophos_anti-virus 4.61.0
cat quick_heal 11.00
aladdin esafe 7.0.17.0
mcafee gateway 2010.1c
emsisoft anti-malware 5.1.0.1
mcafee scan_engine 5.400.0.1158
ikarus ikarus_virus_utilities_t3_command_line_scanner 1.1.97.0
k7computing antivirus 9.77.3565
bitdefender bitdefender 7.2
clamav clamav 0.96.4
pc_tools pc_tools_antivirus 7.0.3.5
alwil avast_antivirus 5.0.677.0
alwil avast_antivirus 4.8.1351.0
kaspersky kaspersky_anti-virus 7.0.0.125
fortinet fortinet_antivirus 4.2.254.0
anti-virus vba32 3.12.14.2
avira antivir 7.11.1.163
gdata-software g_data_antivirus 21
ahnlab v3_internet_security 2011.01.18.00
pandasecurity panda_antivirus 10.0.2.7
CVE-2012-1446 MEDIUM

The ELF file parser in Quick Heal (aka Cat QuickHeal) 11.00, McAfee Anti-Virus Scanning Engine 5.400.0.1158, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Norman Antivirus 6.06.12, eSafe 7.0.17.0, Kaspersky Anti-Virus 7.0.0.125, McAfee Gateway (formerly Webwasher) 2010.1C, Sophos Anti-Virus 4.61.0, CA eTrust Vet Antivirus 36.1.8511, Antiy Labs AVL SDK 2.0.3.7, PC Tools AntiVirus 7.0.3.5, Rising Antivirus 22.83.00.03, Fortinet Antivirus 4.2.254.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an ELF file with a modified encoding field. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different ELF parser implementations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
mcafee gateway 2010.1c
symantec endpoint_protection 11.0
mcafee scan_engine 5.400.0.1158
norman norman_antivirus_&_antispyware 6.06.12
rising-global rising_antivirus 22.83.00.03
pc_tools pc_tools_antivirus 7.0.3.5
kaspersky kaspersky_anti-virus 7.0.0.125
fortinet fortinet_antivirus 4.2.254.0
antiy avl_sdk 2.0.3.7
cat quick_heal 11.00
sophos sophos_anti-virus 4.61.0
ca etrust_vet_antivirus 36.1.8511
pandasecurity panda_antivirus 10.0.2.7
aladdin esafe 7.0.17.0
CVE-2012-1453 MEDIUM

The CAB file parser in Dr.Web 5.0.2.03300, Trend Micro HouseCall 9.120.0.1004, Kaspersky Anti-Virus 7.0.0.125, Sophos Anti-Virus 4.61.0, Trend Micro AntiVirus 9.120.0.1004, McAfee Gateway (formerly Webwasher) 2010.1C, Emsisoft Anti-Malware 5.1.0.1, CA eTrust Vet Antivirus 36.1.8511, Antiy Labs AVL SDK 2.0.3.7, Antimalware Engine 1.1.6402.0 in Microsoft Security Essentials 2.0, Rising Antivirus 22.83.00.03, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Fortinet Antivirus 4.2.254.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via a CAB file with a modified coffFiles field. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different CAB parser implementations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
mcafee gateway 2010.1c
microsoft security_essentials 2.0
trendmicro housecall 9.120.0.1004
emsisoft anti-malware 5.1.0.1
drweb dr.web_antivirus 5.0.2.03300
ikarus ikarus_virus_utilities_t3_command_line_scanner 1.1.97.0
rising-global rising_antivirus 22.83.00.03
trendmicro trend_micro_antivirus 9.120.0.1004
kaspersky kaspersky_anti-virus 7.0.0.125
fortinet fortinet_antivirus 4.2.254.0
antiy avl_sdk 2.0.3.7
sophos sophos_anti-virus 4.61.0
ca etrust_vet_antivirus 36.1.8511
pandasecurity panda_antivirus 10.0.2.7
CVE-2012-1457 MEDIUM

The TAR file parser in Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8.1351.0 and 5.0.677.0, AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Quick Heal (aka Cat QuickHeal) 11.00, ClamAV 0.96.4, Command Antivirus 5.2.11.5, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, F-Prot Antivirus 4.6.2.117, G Data AntiVirus 21, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Jiangmin Antivirus 13.0.900, K7 AntiVirus 9.77.3565, Kaspersky Anti-Virus 7.0.0.125, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwasher) 2010.1C, Antimalware Engine 1.1.6402.0 in Microsoft Security Essentials 2.0, NOD32 Antivirus 5795, Norman Antivirus 6.06.12, PC Tools AntiVirus 7.0.3.5, Rising Antivirus 22.83.00.03, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Trend Micro AntiVirus 9.120.0.1004, Trend Micro HouseCall 9.120.0.1004, VBA32 3.12.14.2, and VirusBuster 13.6.151.0 allows remote attackers to bypass malware detection via a TAR archive entry with a length field that exceeds the total TAR file size. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
virusbuster virusbuster 13.6.151.0
symantec endpoint_protection 11.0
microsoft security_essentials 2.0
trendmicro housecall 9.120.0.1004
norman norman_antivirus_&_antispyware 6.06.12
eset nod32_antivirus 5795
rising-global rising_antivirus 22.83.00.03
trendmicro trend_micro_antivirus 9.120.0.1004
authentium command_antivirus 5.2.11.5
jiangmin jiangmin_antivirus 13.0.900
f-prot f-prot_antivirus 4.6.2.117
avg avg_anti-virus 10.0.0.1190
antiy avl_sdk 2.0.3.7
cat quick_heal 11.00
aladdin esafe 7.0.17.0
mcafee gateway 2010.1c
emsisoft anti-malware 5.1.0.1
mcafee scan_engine 5.400.0.1158
ikarus ikarus_virus_utilities_t3_command_line_scanner 1.1.97.0
bitdefender bitdefender 7.2
k7computing antivirus 9.77.3565
clamav clamav 0.96.4
pc_tools pc_tools_antivirus 7.0.3.5
alwil avast_antivirus 5.0.677.0
alwil avast_antivirus 4.8.1351.0
kaspersky kaspersky_anti-virus 7.0.0.125
anti-virus vba32 3.12.14.2
avira antivir 7.11.1.163
gdata-software g_data_antivirus 21
CVE-2012-1459 MEDIUM

The TAR file parser in AhnLab V3 Internet Security 2011.01.18.00, Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8.1351.0 and 5.0.677.0, AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Quick Heal (aka Cat QuickHeal) 11.00, ClamAV 0.96.4, Command Antivirus 5.2.11.5, Comodo Antivirus 7424, Emsisoft Anti-Malware 5.1.0.1, F-Prot Antivirus 4.6.2.117, F-Secure Anti-Virus 9.0.16160.0, Fortinet Antivirus 4.2.254.0, G Data AntiVirus 21, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Jiangmin Antivirus 13.0.900, K7 AntiVirus 9.77.3565, Kaspersky Anti-Virus 7.0.0.125, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwasher) 2010.1C, Antimalware Engine 1.1.6402.0 in Microsoft Security Essentials 2.0, NOD32 Antivirus 5795, Norman Antivirus 6.06.12, nProtect Anti-Virus 2011-01-17.01, Panda Antivirus 10.0.2.7, PC Tools AntiVirus 7.0.3.5, Rising Antivirus 22.83.00.03, Sophos Anti-Virus 4.61.0, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Trend Micro AntiVirus 9.120.0.1004, Trend Micro HouseCall 9.120.0.1004, VBA32 3.12.14.2, and VirusBuster 13.6.151.0 allows remote attackers to bypass malware detection via a TAR archive entry with a length field corresponding to that entire entry, plus part of the header of the next entry. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
virusbuster virusbuster 13.6.151.0
symantec endpoint_protection 11.0
microsoft security_essentials 2.0
trendmicro housecall 9.120.0.1004
f-secure f-secure_anti-virus 9.0.16160.0
eset nod32_antivirus 5795
norman norman_antivirus_&_antispyware 6.06.12
rising-global rising_antivirus 22.83.00.03
trendmicro trend_micro_antivirus 9.120.0.1004
nprotect nprotect_antivirus 2011-01-17.01
authentium command_antivirus 5.2.11.5
jiangmin jiangmin_antivirus 13.0.900
f-prot f-prot_antivirus 4.6.2.117
antiy avl_sdk 2.0.3.7
avg avg_anti-virus 10.0.0.1190
comodo comodo_antivirus 7424
cat quick_heal 11.00
sophos sophos_anti-virus 4.61.0
mcafee gateway 2010.1c
emsisoft anti-malware 5.1.0.1
mcafee scan_engine 5.400.0.1158
ikarus ikarus_virus_utilities_t3_command_line_scanner 1.1.97.0
k7computing antivirus 9.77.3565
bitdefender bitdefender 7.2
clamav clamav 0.96.4
alwil avast_antivirus 5.0.677.0
pc_tools pc_tools_antivirus 7.0.3.5
alwil avast_antivirus 4.8.1351.0
kaspersky kaspersky_anti-virus 7.0.0.125
fortinet fortinet_antivirus 4.2.254.0
anti-virus vba32 3.12.14.2
avira antivir 7.11.1.163
gdata-software g_data_antivirus 21
ahnlab v3_internet_security 2011.01.18.00
pandasecurity panda_antivirus 10.0.2.7
CVE-2012-1460 MEDIUM

The Gzip file parser in Antiy Labs AVL SDK 2.0.3.7, Quick Heal (aka Cat QuickHeal) 11.00, Command Antivirus 5.2.11.5, eSafe 7.0.17.0, F-Prot Antivirus 4.6.2.117, Jiangmin Antivirus 13.0.900, K7 AntiVirus 9.77.3565, and VBA32 3.12.14.2 allows remote attackers to bypass malware detection via a .tar.gz file with stray bytes at the end. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different Gzip parser implementations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
authentium command_antivirus 5.2.11.5
anti-virus vba32 3.12.14.2
jiangmin jiangmin_antivirus 13.0.900
f-prot f-prot_antivirus 4.6.2.117
antiy avl_sdk 2.0.3.7
cat quick_heal 11.00
k7computing antivirus 9.77.3565
aladdin esafe 7.0.17.0
CVE-2017-10674 MEDIUM

Antiy Antivirus Engine 5.0.0.06281654 allows local users to cause a denial of service (BSOD) via a long third argument in a DeviceIoControl call.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
antiy antivirus_engine 5.0.0.06281654
CVE-2017-10706 LOW

When Antiy Antivirus Engine before 5.0.0.05171547 scans a special ZIP archive, it crashes with a stack-based buffer overflow because a fixed path length is used.

CVSS 2.0

Severity: LOW

Problem Type: CWE-119,

Products Affected

Vendor Product Version
antiy antivirus_engine -
CVE-2018-19650 HIGH

Local attackers can trigger a stack-based buffer overflow on vulnerable installations of Antiy-AVL ATool security management v1.0.0.22. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the processing of IOCTL 0x80002000 by the IRPFile.sys Antiy-AVL ATool kernel driver. The bug is caused by failure to properly validate the length of the user-supplied data, which results in a kernel stack buffer overflow. An attacker can leverage this vulnerability to execute arbitrary code in the context of the kernel, which could lead to privilege escalation and a failed exploit could lead to denial of service.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-787,

Products Affected

Vendor Product Version
antiy anti_virus_lab_atool 1.0.0.22
CVE-2018-20331 HIGH

Local attackers can trigger a Kernel Pool Buffer Overflow in Antiy AVL ATool v1.0.0.22. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the processing of IOCTL 0x80002004 by the ssdt.sys kernel driver. The bug is caused by failure to properly validate the length of the user-supplied data. An attacker can leverage this vulnerability to execute arbitrary code in the context of the kernel, which could lead to privilege escalation. A failed exploit could lead to denial of service.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
antiy anti_virus_lab_atool 1.0.0.22