MidnightBSD

Advisories for ikarus

CVE-2005-3228 MEDIUM

Multiple interpretation error in unspecified versions of Ikarus AntiVirus allows remote attackers to bypass virus detection via a malicious executable in a specially crafted RAR file with malformed central and local headers, which can still be opened by products such as Winrar and PowerZip, even though they are rejected as corrupted by Winzip and BitZipper.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ikarus ikarus_antivirus *
CVE-2005-3375 MEDIUM

Multiple interpretation error in Ikarus demo version allows remote attackers to bypass virus scanning via a file such as BAT, HTML, and EML with an "MZ" magic byte sequence which is normally associated with EXE, which causes the file to be treated as a safe type that could still be executed as a dangerous file type by applications on the end system, as demonstrated by a "triple headed" program that contains EXE, EML, and HTML content, aka the "magic byte bug."

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
ikarus ikarus_antivirus *
CVE-2008-5532 HIGH

Ikarus Virus Utilities T3.1.1.45.0 and possibly T3.1.1.34.0, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-20,

Products Affected

Vendor Product Version
ikarus ikarus_antivirus t3.1.1.34.0
ikarus ikarus_antivirus t3.1.1.45.0
CVE-2012-1423 MEDIUM

The TAR file parser in Command Antivirus 5.2.11.5, Emsisoft Anti-Malware 5.1.0.1, F-Prot Antivirus 4.6.2.117, Fortinet Antivirus 4.2.254.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, K7 AntiVirus 9.77.3565, NOD32 Antivirus 5795, Norman Antivirus 6.06.12, PC Tools AntiVirus 7.0.3.5, Rising Antivirus 22.83.00.03, and VirusBuster 13.6.151.0 allows remote attackers to bypass malware detection via a POSIX TAR file with an initial MZ character sequence. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ikarus ikarus_virus_utilities_t3_command_line_scanner 1.1.97.0
norman norman_antivirus_&_antispyware 6.06.12
virusbuster virusbuster 13.6.151.0
k7computing antivirus 9.77.3565
rising-global rising_antivirus 22.83.00.03
authentium command_antivirus 5.2.11.5
eset nod32_antivirus 5795
f-prot f-prot_antivirus 4.6.2.117
emsisoft anti-malware 5.1.0.1
fortinet fortinet_antivirus 4.2.254.0
pc_tools pc_tools_antivirus 7.0.3.5
CVE-2012-1425 MEDIUM

The TAR file parser in Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, Quick Heal (aka Cat QuickHeal) 11.00, Emsisoft Anti-Malware 5.1.0.1, Fortinet Antivirus 4.2.254.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Jiangmin Antivirus 13.0.900, Kaspersky Anti-Virus 7.0.0.125, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwasher) 2010.1C, NOD32 Antivirus 5795, Norman Antivirus 6.06.12, PC Tools AntiVirus 7.0.3.5, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Trend Micro AntiVirus 9.120.0.1004, and Trend Micro HouseCall 9.120.0.1004 allows remote attackers to bypass malware detection via a POSIX TAR file with an initial \50\4B\03\04 character sequence. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
cat quick_heal 11.00
kaspersky kaspersky_anti-virus 7.0.0.125
jiangmin jiangmin_antivirus 13.0.900
trendmicro housecall 9.120.0.1004
eset nod32_antivirus 5795
trendmicro trend_micro_antivirus 9.120.0.1004
mcafee gateway 2010.1c
pc_tools pc_tools_antivirus 7.0.3.5
ikarus ikarus_virus_utilities_t3_command_line_scanner 1.1.97.0
antiy avl_sdk 2.0.3.7
avira antivir 7.11.1.163
norman norman_antivirus_&_antispyware 6.06.12
mcafee scan_engine 5.400.0.1158
symantec endpoint_protection 11.0
emsisoft anti-malware 5.1.0.1
fortinet fortinet_antivirus 4.2.254.0
CVE-2012-1429 MEDIUM

The ELF file parser in Bitdefender 7.2, Comodo Antivirus 7424, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, F-Secure Anti-Virus 9.0.16160.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwasher) 2010.1C, and nProtect Anti-Virus 2011-01-17.01 allows remote attackers to bypass malware detection via an ELF file with a ustar character sequence at a certain location. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different ELF parser implementations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ikarus ikarus_virus_utilities_t3_command_line_scanner 1.1.97.0
nprotect nprotect_antivirus 2011-01-17.01
mcafee scan_engine 5.400.0.1158
emsisoft anti-malware 5.1.0.1
softwin bitdefender 7.2
mcafee gateway 2010.1c
aladdin esafe 7.0.17.0
comodo comodo_antivirus 7424
f-secure f-secure_anti-virus 9.0.16160.0
CVE-2012-1432 MEDIUM

The Microsoft EXE file parser in Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an EXE file with a \57\69\6E\5A\69\70 character sequence at a certain location. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different EXE parser implementations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ikarus ikarus_virus_utilities_t3_command_line_scanner 1.1.97.0
pandasecurity panda_antivirus 10.0.2.7
emsisoft anti-malware 5.1.0.1
aladdin esafe 7.0.17.0
CVE-2012-1433 MEDIUM

The Microsoft EXE file parser in AhnLab V3 Internet Security 2011.01.18.00, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an EXE file with a \4a\46\49\46 character sequence at a certain location. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different EXE parser implementations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ikarus ikarus_virus_utilities_t3_command_line_scanner 1.1.97.0
pandasecurity panda_antivirus 10.0.2.7
emsisoft anti-malware 5.1.0.1
ahnlab v3_internet_security 2011.01.18.00
aladdin esafe 7.0.17.0
CVE-2012-1434 MEDIUM

The Microsoft EXE file parser in AhnLab V3 Internet Security 2011.01.18.00, Emsisoft Anti-Malware 5.1.0.1, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an EXE file with a \19\04\00\10 character sequence at a certain location. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different EXE parser implementations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ikarus ikarus_virus_utilities_t3_command_line_scanner 1.1.97.0
pandasecurity panda_antivirus 10.0.2.7
emsisoft anti-malware 5.1.0.1
ahnlab v3_internet_security 2011.01.18.00
CVE-2012-1435 MEDIUM

The Microsoft EXE file parser in AhnLab V3 Internet Security 2011.01.18.00, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an EXE file with a \50\4B\4C\49\54\45 character sequence at a certain location. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different EXE parser implementations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ikarus ikarus_virus_utilities_t3_command_line_scanner 1.1.97.0
pandasecurity panda_antivirus 10.0.2.7
emsisoft anti-malware 5.1.0.1
ahnlab v3_internet_security 2011.01.18.00
aladdin esafe 7.0.17.0
CVE-2012-1436 MEDIUM

The Microsoft EXE file parser in AhnLab V3 Internet Security 2011.01.18.00, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an EXE file with a \2D\6C\68 character sequence at a certain location. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different EXE parser implementations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ikarus ikarus_virus_utilities_t3_command_line_scanner 1.1.97.0
pandasecurity panda_antivirus 10.0.2.7
emsisoft anti-malware 5.1.0.1
ahnlab v3_internet_security 2011.01.18.00
aladdin esafe 7.0.17.0
CVE-2012-1443 MEDIUM

The RAR file parser in ClamAV 0.96.4, Rising Antivirus 22.83.00.03, Quick Heal (aka Cat QuickHeal) 11.00, G Data AntiVirus 21, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Command Antivirus 5.2.11.5, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Emsisoft Anti-Malware 5.1.0.1, PC Tools AntiVirus 7.0.3.5, F-Prot Antivirus 4.6.2.117, VirusBuster 13.6.151.0, Fortinet Antivirus 4.2.254.0, Antiy Labs AVL SDK 2.0.3.7, K7 AntiVirus 9.77.3565, Trend Micro HouseCall 9.120.0.1004, Kaspersky Anti-Virus 7.0.0.125, Jiangmin Antivirus 13.0.900, Antimalware Engine 1.1.6402.0 in Microsoft Security Essentials 2.0, Sophos Anti-Virus 4.61.0, NOD32 Antivirus 5795, Avira AntiVir 7.11.1.163, Norman Antivirus 6.06.12, McAfee Anti-Virus Scanning Engine 5.400.0.1158, Panda Antivirus 10.0.2.7, McAfee Gateway (formerly Webwasher) 2010.1C, Trend Micro AntiVirus 9.120.0.1004, Comodo Antivirus 7424, Bitdefender 7.2, eSafe 7.0.17.0, F-Secure Anti-Virus 9.0.16160.0, nProtect Anti-Virus 2011-01-17.01, AhnLab V3 Internet Security 2011.01.18.00, AVG Anti-Virus 10.0.0.1190, avast! Antivirus 4.8.1351.0 and 5.0.677.0, and VBA32 3.12.14.2 allows user-assisted remote attackers to bypass malware detection via a RAR file with an initial MZ character sequence. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different RAR parser implementations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
clamav clamav 0.96.4
sophos sophos_anti-virus 4.61.0
cat quick_heal 11.00
kaspersky kaspersky_anti-virus 7.0.0.125
trendmicro housecall 9.120.0.1004
trendmicro trend_micro_antivirus 9.120.0.1004
mcafee gateway 2010.1c
aladdin esafe 7.0.17.0
microsoft security_essentials 2.0
pc_tools pc_tools_antivirus 7.0.3.5
norman norman_antivirus_&_antispyware 6.06.12
mcafee scan_engine 5.400.0.1158
avg avg_anti-virus 10.0.0.1190
rising-global rising_antivirus 22.83.00.03
alwil avast_antivirus 5.0.677.0
authentium command_antivirus 5.2.11.5
alwil avast_antivirus 4.8.1351.0
symantec endpoint_protection 11.0
fortinet fortinet_antivirus 4.2.254.0
ahnlab v3_internet_security 2011.01.18.00
comodo comodo_antivirus 7424
gdata-software g_data_antivirus 21
anti-virus vba32 3.12.14.2
jiangmin jiangmin_antivirus 13.0.900
k7computing antivirus 9.77.3565
eset nod32_antivirus 5795
f-prot f-prot_antivirus 4.6.2.117
ikarus ikarus_virus_utilities_t3_command_line_scanner 1.1.97.0
antiy avl_sdk 2.0.3.7
avira antivir 7.11.1.163
pandasecurity panda_antivirus 10.0.2.7
nprotect nprotect_antivirus 2011-01-17.01
virusbuster virusbuster 13.6.151.0
bitdefender bitdefender 7.2
emsisoft anti-malware 5.1.0.1
f-secure f-secure_anti-virus 9.0.16160.0
CVE-2012-1448 MEDIUM

The CAB file parser in Quick Heal (aka Cat QuickHeal) 11.00, Trend Micro AntiVirus 9.120.0.1004, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Trend Micro HouseCall 9.120.0.1004, and Emsisoft Anti-Malware 5.1.0.1 allows remote attackers to bypass malware detection via a CAB file with a modified cbCabinet field. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different CAB parser implementations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ikarus ikarus_virus_utilities_t3_command_line_scanner 1.1.97.0
cat quick_heal 11.00
trendmicro housecall 9.120.0.1004
emsisoft anti-malware 5.1.0.1
trendmicro trend_micro_antivirus 9.120.0.1004
CVE-2012-1450 MEDIUM

The CAB file parser in Emsisoft Anti-Malware 5.1.0.1, Sophos Anti-Virus 4.61.0, and Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0 allows remote attackers to bypass malware detection via a CAB file with a modified reserved3 field. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different CAB parser implementations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ikarus ikarus_virus_utilities_t3_command_line_scanner 1.1.97.0
sophos sophos_anti-virus 4.61.0
emsisoft anti-malware 5.1.0.1
CVE-2012-1451 MEDIUM

The CAB file parser in Emsisoft Anti-Malware 5.1.0.1 and Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0 allows remote attackers to bypass malware detection via a CAB file with a modified reserved2 field. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different CAB parser implementations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ikarus ikarus_virus_utilities_t3_command_line_scanner 1.1.97.0
emsisoft anti-malware 5.1.0.1
CVE-2012-1452 MEDIUM

The CAB file parser in Emsisoft Anti-Malware 5.1.0.1, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, and Quick Heal (aka Cat QuickHeal) 11.00 allows remote attackers to bypass malware detection via a CAB file with a modified reserved1 field. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different CAB parser implementations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ikarus ikarus_virus_utilities_t3_command_line_scanner 1.1.97.0
cat quick_heal 11.00
emsisoft anti-malware 5.1.0.1
CVE-2012-1453 MEDIUM

The CAB file parser in Dr.Web 5.0.2.03300, Trend Micro HouseCall 9.120.0.1004, Kaspersky Anti-Virus 7.0.0.125, Sophos Anti-Virus 4.61.0, Trend Micro AntiVirus 9.120.0.1004, McAfee Gateway (formerly Webwasher) 2010.1C, Emsisoft Anti-Malware 5.1.0.1, CA eTrust Vet Antivirus 36.1.8511, Antiy Labs AVL SDK 2.0.3.7, Antimalware Engine 1.1.6402.0 in Microsoft Security Essentials 2.0, Rising Antivirus 22.83.00.03, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Fortinet Antivirus 4.2.254.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via a CAB file with a modified coffFiles field. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different CAB parser implementations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
sophos sophos_anti-virus 4.61.0
kaspersky kaspersky_anti-virus 7.0.0.125
trendmicro housecall 9.120.0.1004
trendmicro trend_micro_antivirus 9.120.0.1004
mcafee gateway 2010.1c
microsoft security_essentials 2.0
ikarus ikarus_virus_utilities_t3_command_line_scanner 1.1.97.0
antiy avl_sdk 2.0.3.7
pandasecurity panda_antivirus 10.0.2.7
ca etrust_vet_antivirus 36.1.8511
drweb dr.web_antivirus 5.0.2.03300
rising-global rising_antivirus 22.83.00.03
emsisoft anti-malware 5.1.0.1
fortinet fortinet_antivirus 4.2.254.0
CVE-2012-1456 MEDIUM

The TAR file parser in AVG Anti-Virus 10.0.0.1190, Quick Heal (aka Cat QuickHeal) 11.00, Comodo Antivirus 7424, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, F-Prot Antivirus 4.6.2.117, Fortinet Antivirus 4.2.254.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Jiangmin Antivirus 13.0.900, Kaspersky Anti-Virus 7.0.0.125, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwasher) 2010.1C, NOD32 Antivirus 5795, Norman Antivirus 6.06.12, Panda Antivirus 10.0.2.7, Rising Antivirus 22.83.00.03, Sophos Anti-Virus 4.61.0, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Trend Micro AntiVirus 9.120.0.1004, and Trend Micro HouseCall 9.120.0.1004 allows remote attackers to bypass malware detection via a TAR file with an appended ZIP file. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
sophos sophos_anti-virus 4.61.0
cat quick_heal 11.00
kaspersky kaspersky_anti-virus 7.0.0.125
jiangmin jiangmin_antivirus 13.0.900
trendmicro housecall 9.120.0.1004
eset nod32_antivirus 5795
f-prot f-prot_antivirus 4.6.2.117
trendmicro trend_micro_antivirus 9.120.0.1004
mcafee gateway 2010.1c
aladdin esafe 7.0.17.0
ikarus ikarus_virus_utilities_t3_command_line_scanner 1.1.97.0
pandasecurity panda_antivirus 10.0.2.7
norman norman_antivirus_&_antispyware 6.06.12
mcafee scan_engine 5.400.0.1158
avg avg_anti-virus 10.0.0.1190
rising-global rising_antivirus 22.83.00.03
symantec endpoint_protection 11.0
emsisoft anti-malware 5.1.0.1
fortinet fortinet_antivirus 4.2.254.0
comodo comodo_antivirus 7424
CVE-2012-1457 MEDIUM

The TAR file parser in Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8.1351.0 and 5.0.677.0, AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Quick Heal (aka Cat QuickHeal) 11.00, ClamAV 0.96.4, Command Antivirus 5.2.11.5, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, F-Prot Antivirus 4.6.2.117, G Data AntiVirus 21, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Jiangmin Antivirus 13.0.900, K7 AntiVirus 9.77.3565, Kaspersky Anti-Virus 7.0.0.125, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwasher) 2010.1C, Antimalware Engine 1.1.6402.0 in Microsoft Security Essentials 2.0, NOD32 Antivirus 5795, Norman Antivirus 6.06.12, PC Tools AntiVirus 7.0.3.5, Rising Antivirus 22.83.00.03, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Trend Micro AntiVirus 9.120.0.1004, Trend Micro HouseCall 9.120.0.1004, VBA32 3.12.14.2, and VirusBuster 13.6.151.0 allows remote attackers to bypass malware detection via a TAR archive entry with a length field that exceeds the total TAR file size. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
clamav clamav 0.96.4
cat quick_heal 11.00
kaspersky kaspersky_anti-virus 7.0.0.125
trendmicro housecall 9.120.0.1004
trendmicro trend_micro_antivirus 9.120.0.1004
mcafee gateway 2010.1c
aladdin esafe 7.0.17.0
microsoft security_essentials 2.0
pc_tools pc_tools_antivirus 7.0.3.5
norman norman_antivirus_&_antispyware 6.06.12
mcafee scan_engine 5.400.0.1158
avg avg_anti-virus 10.0.0.1190
rising-global rising_antivirus 22.83.00.03
alwil avast_antivirus 5.0.677.0
authentium command_antivirus 5.2.11.5
alwil avast_antivirus 4.8.1351.0
symantec endpoint_protection 11.0
gdata-software g_data_antivirus 21
anti-virus vba32 3.12.14.2
jiangmin jiangmin_antivirus 13.0.900
k7computing antivirus 9.77.3565
eset nod32_antivirus 5795
f-prot f-prot_antivirus 4.6.2.117
ikarus ikarus_virus_utilities_t3_command_line_scanner 1.1.97.0
antiy avl_sdk 2.0.3.7
avira antivir 7.11.1.163
virusbuster virusbuster 13.6.151.0
bitdefender bitdefender 7.2
emsisoft anti-malware 5.1.0.1
CVE-2012-1459 MEDIUM

The TAR file parser in AhnLab V3 Internet Security 2011.01.18.00, Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8.1351.0 and 5.0.677.0, AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Quick Heal (aka Cat QuickHeal) 11.00, ClamAV 0.96.4, Command Antivirus 5.2.11.5, Comodo Antivirus 7424, Emsisoft Anti-Malware 5.1.0.1, F-Prot Antivirus 4.6.2.117, F-Secure Anti-Virus 9.0.16160.0, Fortinet Antivirus 4.2.254.0, G Data AntiVirus 21, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Jiangmin Antivirus 13.0.900, K7 AntiVirus 9.77.3565, Kaspersky Anti-Virus 7.0.0.125, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwasher) 2010.1C, Antimalware Engine 1.1.6402.0 in Microsoft Security Essentials 2.0, NOD32 Antivirus 5795, Norman Antivirus 6.06.12, nProtect Anti-Virus 2011-01-17.01, Panda Antivirus 10.0.2.7, PC Tools AntiVirus 7.0.3.5, Rising Antivirus 22.83.00.03, Sophos Anti-Virus 4.61.0, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Trend Micro AntiVirus 9.120.0.1004, Trend Micro HouseCall 9.120.0.1004, VBA32 3.12.14.2, and VirusBuster 13.6.151.0 allows remote attackers to bypass malware detection via a TAR archive entry with a length field corresponding to that entire entry, plus part of the header of the next entry. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
clamav clamav 0.96.4
sophos sophos_anti-virus 4.61.0
cat quick_heal 11.00
kaspersky kaspersky_anti-virus 7.0.0.125
trendmicro housecall 9.120.0.1004
trendmicro trend_micro_antivirus 9.120.0.1004
mcafee gateway 2010.1c
microsoft security_essentials 2.0
pc_tools pc_tools_antivirus 7.0.3.5
norman norman_antivirus_&_antispyware 6.06.12
mcafee scan_engine 5.400.0.1158
avg avg_anti-virus 10.0.0.1190
rising-global rising_antivirus 22.83.00.03
alwil avast_antivirus 5.0.677.0
authentium command_antivirus 5.2.11.5
alwil avast_antivirus 4.8.1351.0
symantec endpoint_protection 11.0
fortinet fortinet_antivirus 4.2.254.0
ahnlab v3_internet_security 2011.01.18.00
comodo comodo_antivirus 7424
gdata-software g_data_antivirus 21
anti-virus vba32 3.12.14.2
jiangmin jiangmin_antivirus 13.0.900
k7computing antivirus 9.77.3565
eset nod32_antivirus 5795
f-prot f-prot_antivirus 4.6.2.117
ikarus ikarus_virus_utilities_t3_command_line_scanner 1.1.97.0
antiy avl_sdk 2.0.3.7
avira antivir 7.11.1.163
pandasecurity panda_antivirus 10.0.2.7
nprotect nprotect_antivirus 2011-01-17.01
virusbuster virusbuster 13.6.151.0
bitdefender bitdefender 7.2
emsisoft anti-malware 5.1.0.1
f-secure f-secure_anti-virus 9.0.16160.0
CVE-2012-1461 MEDIUM

The Gzip file parser in AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Command Antivirus 5.2.11.5, Emsisoft Anti-Malware 5.1.0.1, F-Secure Anti-Virus 9.0.16160.0, Fortinet Antivirus 4.2.254.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Jiangmin Antivirus 13.0.900, K7 AntiVirus 9.77.3565, Kaspersky Anti-Virus 7.0.0.125, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwasher) 2010.1C, NOD32 Antivirus 5795, Norman Antivirus 6.06.12, Rising Antivirus 22.83.00.03, Sophos Anti-Virus 4.61.0, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Trend Micro AntiVirus 9.120.0.1004, Trend Micro HouseCall 9.120.0.1004, and VBA32 3.12.14.2 allows remote attackers to bypass malware detection via a .tar.gz file with multiple compressed streams. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different Gzip parser implementations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
sophos sophos_anti-virus 4.61.0
anti-virus vba32 3.12.14.2
kaspersky kaspersky_anti-virus 7.0.0.125
jiangmin jiangmin_antivirus 13.0.900
k7computing antivirus 9.77.3565
trendmicro housecall 9.120.0.1004
eset nod32_antivirus 5795
trendmicro trend_micro_antivirus 9.120.0.1004
mcafee gateway 2010.1c
ikarus ikarus_virus_utilities_t3_command_line_scanner 1.1.97.0
norman norman_antivirus_&_antispyware 6.06.12
mcafee scan_engine 5.400.0.1158
avg avg_anti-virus 10.0.0.1190
bitdefender bitdefender 7.2
rising-global rising_antivirus 22.83.00.03
authentium command_antivirus 5.2.11.5
symantec endpoint_protection 11.0
emsisoft anti-malware 5.1.0.1
fortinet fortinet_antivirus 4.2.254.0
f-secure f-secure_anti-virus 9.0.16160.0
CVE-2012-1462 MEDIUM

The ZIP file parser in AhnLab V3 Internet Security 2011.01.18.00, AVG Anti-Virus 10.0.0.1190, Quick Heal (aka Cat QuickHeal) 11.00, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, Fortinet Antivirus 4.2.254.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Jiangmin Antivirus 13.0.900, Kaspersky Anti-Virus 7.0.0.125, Norman Antivirus 6.06.12, Sophos Anti-Virus 4.61.0, and AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11 allows remote attackers to bypass malware detection via a ZIP file containing an invalid block of data at the beginning. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different ZIP parser implementations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ikarus ikarus_virus_utilities_t3_command_line_scanner 1.1.97.0
cat quick_heal 11.00
avg avg_anti-virus 10.0.0.1190
kaspersky kaspersky_anti-virus 7.0.0.125
jiangmin jiangmin_antivirus 13.0.900
symantec endpoint_protection 11.0
emsisoft anti-malware 5.1.0.1
fortinet fortinet_antivirus 4.2.254.0
ahnlab v3_internet_security 2011.01.18.00
aladdin esafe 7.0.17.0