MidnightBSD

Advisories for rising-global

CVE-2010-1591 HIGH

Beijing Rising International Rising Antivirus 2008 through 2010 does not properly validate input to certain IOCTLs, including 0x83003C07, which allows local users to gain privileges via crafted IOCTL requests to the (1) HookCont.sys, (2) HookNtos.sys, (3) HOOKREG.sys, or (4) HookSys.sys device driver; or the (5) RsNTGdi.sys kernel module, reachable through \Device\RSNTGDI.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-20,

Products Affected

Vendor Product Version
rising-global rising_antivirus 2009
rising-global rising_antivirus 2008
rising-global rising_antivirus 2010
CVE-2012-1420 MEDIUM

The TAR file parser in Quick Heal (aka Cat QuickHeal) 11.00, Command Antivirus 5.2.11.5, F-Prot Antivirus 4.6.2.117, Fortinet Antivirus 4.2.254.0, K7 AntiVirus 9.77.3565, Kaspersky Anti-Virus 7.0.0.125, Antimalware Engine 1.1.6402.0 in Microsoft Security Essentials 2.0, NOD32 Antivirus 5795, Norman Antivirus 6.06.12, Panda Antivirus 10.0.2.7, and Rising Antivirus 22.83.00.03 allows remote attackers to bypass malware detection via a POSIX TAR file with an initial \7fELF character sequence. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
k7computing antivirus 9.77.3565
eset nod32_antivirus 5795
norman norman_antivirus_&_antispyware 6.06.12
authentium command_antivirus 5.2.11.5
pandasecurity panda_antivirus 10.0.2.7
cat quick_heal 11.00
microsoft security_essentials 2.0
f-prot f-prot_antivirus 4.6.2.117
fortinet fortinet_antivirus 4.2.254.0
kaspersky kaspersky_anti-virus 7.0.0.125
rising-global rising_antivirus 22.83.00.03
CVE-2012-1421 MEDIUM

The TAR file parser in Quick Heal (aka Cat QuickHeal) 11.00, Norman Antivirus 6.06.12, Rising Antivirus 22.83.00.03, and AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11 allows remote attackers to bypass malware detection via a POSIX TAR file with an initial MSCF character sequence. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
symantec endpoint_protection 11.0
norman norman_antivirus_&_antispyware 6.06.12
cat quick_heal 11.00
rising-global rising_antivirus 22.83.00.03
CVE-2012-1422 MEDIUM

The TAR file parser in Quick Heal (aka Cat QuickHeal) 11.00, NOD32 Antivirus 5795, Norman Antivirus 6.06.12, and Rising Antivirus 22.83.00.03 allows remote attackers to bypass malware detection via a POSIX TAR file with an initial ITSF character sequence. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
eset nod32_antivirus 5795
norman norman_antivirus_&_antispyware 6.06.12
cat quick_heal 11.00
rising-global rising_antivirus 22.83.00.03
CVE-2012-1423 MEDIUM

The TAR file parser in Command Antivirus 5.2.11.5, Emsisoft Anti-Malware 5.1.0.1, F-Prot Antivirus 4.6.2.117, Fortinet Antivirus 4.2.254.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, K7 AntiVirus 9.77.3565, NOD32 Antivirus 5795, Norman Antivirus 6.06.12, PC Tools AntiVirus 7.0.3.5, Rising Antivirus 22.83.00.03, and VirusBuster 13.6.151.0 allows remote attackers to bypass malware detection via a POSIX TAR file with an initial MZ character sequence. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ikarus ikarus_virus_utilities_t3_command_line_scanner 1.1.97.0
pc_tools pc_tools_antivirus 7.0.3.5
emsisoft anti-malware 5.1.0.1
k7computing antivirus 9.77.3565
eset nod32_antivirus 5795
virusbuster virusbuster 13.6.151.0
norman norman_antivirus_&_antispyware 6.06.12
authentium command_antivirus 5.2.11.5
f-prot f-prot_antivirus 4.6.2.117
fortinet fortinet_antivirus 4.2.254.0
rising-global rising_antivirus 22.83.00.03
CVE-2012-1426 MEDIUM

The TAR file parser in Quick Heal (aka Cat QuickHeal) 11.00, Command Antivirus 5.2.11.5, F-Prot Antivirus 4.6.2.117, K7 AntiVirus 9.77.3565, Norman Antivirus 6.06.12, and Rising Antivirus 22.83.00.03 allows remote attackers to bypass malware detection via a POSIX TAR file with an initial \42\5A\68 character sequence. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
k7computing antivirus 9.77.3565
norman norman_antivirus_&_antispyware 6.06.12
authentium command_antivirus 5.2.11.5
cat quick_heal 11.00
f-prot f-prot_antivirus 4.6.2.117
rising-global rising_antivirus 22.83.00.03
CVE-2012-1430 MEDIUM

The ELF file parser in Bitdefender 7.2, Comodo Antivirus 7424, eSafe 7.0.17.0, F-Secure Anti-Virus 9.0.16160.0, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwasher) 2010.1C, nProtect Anti-Virus 2011-01-17.01, Sophos Anti-Virus 4.61.0, and Rising Antivirus 22.83.00.03 allows remote attackers to bypass malware detection via an ELF file with a \19\04\00\10 character sequence at a certain location. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different ELF parser implementations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
bitdefender bitdefender 7.2
mcafee scan_engine 5.400.0.1158
aladdin esafe 7.0.17.0
comodo comodo_antivirus 7424
sophos sophos_anti-virus 4.61.0
f-secure anti-virus 9.0.16160.0
rising-global rising_antivirus 22.83.00.03
mcafee gateway 2010.1c
nprotect nprotect_antivirus 2011-01-17.01
CVE-2012-1431 MEDIUM

The ELF file parser in Bitdefender 7.2, Command Antivirus 5.2.11.5, Comodo Antivirus 7424, eSafe 7.0.17.0, F-Prot Antivirus 4.6.2.117, F-Secure Anti-Virus 9.0.16160.0, McAfee Gateway (formerly Webwasher) 2010.1C, nProtect Anti-Virus 2011-01-17.01, Sophos Anti-Virus 4.61.0, and Rising Antivirus 22.83.00.03 allows remote attackers to bypass malware detection via an ELF file with a \4a\46\49\46 character sequence at a certain location. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different ELF parser implementations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
f-secure f-secure_anti-virus 9.0.16160.0
bitdefender bitdefender 7.2
aladdin esafe 7.0.17.0
comodo comodo_antivirus 7424
sophos sophos_anti-virus 4.61.0
authentium command_antivirus 5.2.11.5
f-prot f-prot_antivirus 4.6.2.117
rising-global rising_antivirus 22.83.00.03
mcafee gateway 2010.1c
nprotect nprotect_antivirus 2011-01-17.01
CVE-2012-1439 MEDIUM

The ELF file parser in eSafe 7.0.17.0, Rising Antivirus 22.83.00.03, Fortinet Antivirus 4.2.254.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an ELF file with a modified padding field. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different ELF parser implementations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
aladdin esafe 7.0.17.0
pandasecurity panda_antivirus 10.0.2.7
fortinet fortinet_antivirus 4.2.254.0
rising-global rising_antivirus 22.83.00.03
CVE-2012-1442 MEDIUM

The ELF file parser in Quick Heal (aka Cat QuickHeal) 11.00, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwasher) 2010.1C, eSafe 7.0.17.0, Kaspersky Anti-Virus 7.0.0.125, F-Secure Anti-Virus 9.0.16160.0, Sophos Anti-Virus 4.61.0, Antiy Labs AVL SDK 2.0.3.7, Rising Antivirus 22.83.00.03, Fortinet Antivirus 4.2.254.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an ELF file with a modified class field. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different ELF parser implementations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
f-secure f-secure_anti-virus 9.0.16160.0
mcafee scan_engine 5.400.0.1158
aladdin esafe 7.0.17.0
antiy avl_sdk 2.0.3.7
sophos sophos_anti-virus 4.61.0
pandasecurity panda_antivirus 10.0.2.7
cat quick_heal 11.00
fortinet fortinet_antivirus 4.2.254.0
kaspersky kaspersky_anti-virus 7.0.0.125
rising-global rising_antivirus 22.83.00.03
mcafee gateway 2010.1c
CVE-2012-1443 MEDIUM

The RAR file parser in ClamAV 0.96.4, Rising Antivirus 22.83.00.03, Quick Heal (aka Cat QuickHeal) 11.00, G Data AntiVirus 21, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Command Antivirus 5.2.11.5, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Emsisoft Anti-Malware 5.1.0.1, PC Tools AntiVirus 7.0.3.5, F-Prot Antivirus 4.6.2.117, VirusBuster 13.6.151.0, Fortinet Antivirus 4.2.254.0, Antiy Labs AVL SDK 2.0.3.7, K7 AntiVirus 9.77.3565, Trend Micro HouseCall 9.120.0.1004, Kaspersky Anti-Virus 7.0.0.125, Jiangmin Antivirus 13.0.900, Antimalware Engine 1.1.6402.0 in Microsoft Security Essentials 2.0, Sophos Anti-Virus 4.61.0, NOD32 Antivirus 5795, Avira AntiVir 7.11.1.163, Norman Antivirus 6.06.12, McAfee Anti-Virus Scanning Engine 5.400.0.1158, Panda Antivirus 10.0.2.7, McAfee Gateway (formerly Webwasher) 2010.1C, Trend Micro AntiVirus 9.120.0.1004, Comodo Antivirus 7424, Bitdefender 7.2, eSafe 7.0.17.0, F-Secure Anti-Virus 9.0.16160.0, nProtect Anti-Virus 2011-01-17.01, AhnLab V3 Internet Security 2011.01.18.00, AVG Anti-Virus 10.0.0.1190, avast! Antivirus 4.8.1351.0 and 5.0.677.0, and VBA32 3.12.14.2 allows user-assisted remote attackers to bypass malware detection via a RAR file with an initial MZ character sequence. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different RAR parser implementations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
emsisoft anti-malware 5.1.0.1
k7computing antivirus 9.77.3565
f-secure f-secure_anti-virus 9.0.16160.0
avg avg_anti-virus 10.0.0.1190
authentium command_antivirus 5.2.11.5
microsoft security_essentials 2.0
f-prot f-prot_antivirus 4.6.2.117
fortinet fortinet_antivirus 4.2.254.0
trendmicro trend_micro_antivirus 9.120.0.1004
mcafee gateway 2010.1c
ahnlab v3_internet_security 2011.01.18.00
pc_tools pc_tools_antivirus 7.0.3.5
jiangmin jiangmin_antivirus 13.0.900
bitdefender bitdefender 7.2
mcafee scan_engine 5.400.0.1158
eset nod32_antivirus 5795
norman norman_antivirus_&_antispyware 6.06.12
trendmicro housecall 9.120.0.1004
nprotect nprotect_antivirus 2011-01-17.01
ikarus ikarus_virus_utilities_t3_command_line_scanner 1.1.97.0
anti-virus vba32 3.12.14.2
symantec endpoint_protection 11.0
gdata-software g_data_antivirus 21
sophos sophos_anti-virus 4.61.0
avira antivir 7.11.1.163
cat quick_heal 11.00
alwil avast_antivirus 4.8.1351.0
rising-global rising_antivirus 22.83.00.03
clamav clamav 0.96.4
alwil avast_antivirus 5.0.677.0
aladdin esafe 7.0.17.0
comodo comodo_antivirus 7424
virusbuster virusbuster 13.6.151.0
antiy avl_sdk 2.0.3.7
pandasecurity panda_antivirus 10.0.2.7
kaspersky kaspersky_anti-virus 7.0.0.125
CVE-2012-1445 MEDIUM

The ELF file parser in eSafe 7.0.17.0, Rising Antivirus 22.83.00.03, Fortinet Antivirus 4.2.254.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an ELF file with a modified abi field. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different ELF parser implementations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
aladdin esafe 7.0.17.0
pandasecurity panda_antivirus 10.0.2.7
fortinet fortinet_antivirus 4.2.254.0
rising-global rising_antivirus 22.83.00.03
CVE-2012-1446 MEDIUM

The ELF file parser in Quick Heal (aka Cat QuickHeal) 11.00, McAfee Anti-Virus Scanning Engine 5.400.0.1158, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Norman Antivirus 6.06.12, eSafe 7.0.17.0, Kaspersky Anti-Virus 7.0.0.125, McAfee Gateway (formerly Webwasher) 2010.1C, Sophos Anti-Virus 4.61.0, CA eTrust Vet Antivirus 36.1.8511, Antiy Labs AVL SDK 2.0.3.7, PC Tools AntiVirus 7.0.3.5, Rising Antivirus 22.83.00.03, Fortinet Antivirus 4.2.254.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an ELF file with a modified encoding field. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different ELF parser implementations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
symantec endpoint_protection 11.0
ca etrust_vet_antivirus 36.1.8511
sophos sophos_anti-virus 4.61.0
cat quick_heal 11.00
fortinet fortinet_antivirus 4.2.254.0
rising-global rising_antivirus 22.83.00.03
mcafee gateway 2010.1c
pc_tools pc_tools_antivirus 7.0.3.5
mcafee scan_engine 5.400.0.1158
aladdin esafe 7.0.17.0
antiy avl_sdk 2.0.3.7
norman norman_antivirus_&_antispyware 6.06.12
pandasecurity panda_antivirus 10.0.2.7
kaspersky kaspersky_anti-virus 7.0.0.125
CVE-2012-1449 MEDIUM

The CAB file parser in NOD32 Antivirus 5795 and Rising Antivirus 22.83.00.03 allows remote attackers to bypass malware detection via a CAB file with a modified vMajor field. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different CAB parser implementations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
eset nod32_antivirus 5795
rising-global rising_antivirus 22.83.00.03
CVE-2012-1453 MEDIUM

The CAB file parser in Dr.Web 5.0.2.03300, Trend Micro HouseCall 9.120.0.1004, Kaspersky Anti-Virus 7.0.0.125, Sophos Anti-Virus 4.61.0, Trend Micro AntiVirus 9.120.0.1004, McAfee Gateway (formerly Webwasher) 2010.1C, Emsisoft Anti-Malware 5.1.0.1, CA eTrust Vet Antivirus 36.1.8511, Antiy Labs AVL SDK 2.0.3.7, Antimalware Engine 1.1.6402.0 in Microsoft Security Essentials 2.0, Rising Antivirus 22.83.00.03, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Fortinet Antivirus 4.2.254.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via a CAB file with a modified coffFiles field. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different CAB parser implementations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ikarus ikarus_virus_utilities_t3_command_line_scanner 1.1.97.0
emsisoft anti-malware 5.1.0.1
ca etrust_vet_antivirus 36.1.8511
sophos sophos_anti-virus 4.61.0
microsoft security_essentials 2.0
fortinet fortinet_antivirus 4.2.254.0
trendmicro trend_micro_antivirus 9.120.0.1004
drweb dr.web_antivirus 5.0.2.03300
rising-global rising_antivirus 22.83.00.03
mcafee gateway 2010.1c
antiy avl_sdk 2.0.3.7
pandasecurity panda_antivirus 10.0.2.7
trendmicro housecall 9.120.0.1004
kaspersky kaspersky_anti-virus 7.0.0.125
CVE-2012-1454 MEDIUM

The ELF file parser in Dr.Web 5.0.2.03300, eSafe 7.0.17.0, McAfee Gateway (formerly Webwasher) 2010.1C, Rising Antivirus 22.83.00.03, Fortinet Antivirus 4.2.254.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an ELF file with a modified ei_version field. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different ELF parser implementations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
aladdin esafe 7.0.17.0
pandasecurity panda_antivirus 10.0.2.7
fortinet fortinet_antivirus 4.2.254.0
drweb dr.web_antivirus 5.0.2.03300
rising-global rising_antivirus 22.83.00.03
mcafee gateway 2010.1c
CVE-2012-1455 MEDIUM

The CAB file parser in NOD32 Antivirus 5795 and Rising Antivirus 22.83.00.03 allows remote attackers to bypass malware detection via a CAB file with a modified vMinor version field. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different CAB parser implementations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
eset nod32_antivirus 5795
rising-global rising_antivirus 22.83.00.03
CVE-2012-1456 MEDIUM

The TAR file parser in AVG Anti-Virus 10.0.0.1190, Quick Heal (aka Cat QuickHeal) 11.00, Comodo Antivirus 7424, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, F-Prot Antivirus 4.6.2.117, Fortinet Antivirus 4.2.254.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Jiangmin Antivirus 13.0.900, Kaspersky Anti-Virus 7.0.0.125, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwasher) 2010.1C, NOD32 Antivirus 5795, Norman Antivirus 6.06.12, Panda Antivirus 10.0.2.7, Rising Antivirus 22.83.00.03, Sophos Anti-Virus 4.61.0, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Trend Micro AntiVirus 9.120.0.1004, and Trend Micro HouseCall 9.120.0.1004 allows remote attackers to bypass malware detection via a TAR file with an appended ZIP file. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ikarus ikarus_virus_utilities_t3_command_line_scanner 1.1.97.0
emsisoft anti-malware 5.1.0.1
symantec endpoint_protection 11.0
avg avg_anti-virus 10.0.0.1190
sophos sophos_anti-virus 4.61.0
cat quick_heal 11.00
f-prot f-prot_antivirus 4.6.2.117
fortinet fortinet_antivirus 4.2.254.0
trendmicro trend_micro_antivirus 9.120.0.1004
rising-global rising_antivirus 22.83.00.03
mcafee gateway 2010.1c
jiangmin jiangmin_antivirus 13.0.900
mcafee scan_engine 5.400.0.1158
eset nod32_antivirus 5795
aladdin esafe 7.0.17.0
comodo comodo_antivirus 7424
norman norman_antivirus_&_antispyware 6.06.12
pandasecurity panda_antivirus 10.0.2.7
trendmicro housecall 9.120.0.1004
kaspersky kaspersky_anti-virus 7.0.0.125
CVE-2012-1457 MEDIUM

The TAR file parser in Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8.1351.0 and 5.0.677.0, AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Quick Heal (aka Cat QuickHeal) 11.00, ClamAV 0.96.4, Command Antivirus 5.2.11.5, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, F-Prot Antivirus 4.6.2.117, G Data AntiVirus 21, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Jiangmin Antivirus 13.0.900, K7 AntiVirus 9.77.3565, Kaspersky Anti-Virus 7.0.0.125, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwasher) 2010.1C, Antimalware Engine 1.1.6402.0 in Microsoft Security Essentials 2.0, NOD32 Antivirus 5795, Norman Antivirus 6.06.12, PC Tools AntiVirus 7.0.3.5, Rising Antivirus 22.83.00.03, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Trend Micro AntiVirus 9.120.0.1004, Trend Micro HouseCall 9.120.0.1004, VBA32 3.12.14.2, and VirusBuster 13.6.151.0 allows remote attackers to bypass malware detection via a TAR archive entry with a length field that exceeds the total TAR file size. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
emsisoft anti-malware 5.1.0.1
k7computing antivirus 9.77.3565
avg avg_anti-virus 10.0.0.1190
authentium command_antivirus 5.2.11.5
microsoft security_essentials 2.0
f-prot f-prot_antivirus 4.6.2.117
trendmicro trend_micro_antivirus 9.120.0.1004
mcafee gateway 2010.1c
pc_tools pc_tools_antivirus 7.0.3.5
jiangmin jiangmin_antivirus 13.0.900
bitdefender bitdefender 7.2
mcafee scan_engine 5.400.0.1158
eset nod32_antivirus 5795
norman norman_antivirus_&_antispyware 6.06.12
trendmicro housecall 9.120.0.1004
ikarus ikarus_virus_utilities_t3_command_line_scanner 1.1.97.0
anti-virus vba32 3.12.14.2
symantec endpoint_protection 11.0
gdata-software g_data_antivirus 21
avira antivir 7.11.1.163
cat quick_heal 11.00
alwil avast_antivirus 4.8.1351.0
rising-global rising_antivirus 22.83.00.03
clamav clamav 0.96.4
alwil avast_antivirus 5.0.677.0
aladdin esafe 7.0.17.0
virusbuster virusbuster 13.6.151.0
antiy avl_sdk 2.0.3.7
kaspersky kaspersky_anti-virus 7.0.0.125
CVE-2012-1459 MEDIUM

The TAR file parser in AhnLab V3 Internet Security 2011.01.18.00, Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8.1351.0 and 5.0.677.0, AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Quick Heal (aka Cat QuickHeal) 11.00, ClamAV 0.96.4, Command Antivirus 5.2.11.5, Comodo Antivirus 7424, Emsisoft Anti-Malware 5.1.0.1, F-Prot Antivirus 4.6.2.117, F-Secure Anti-Virus 9.0.16160.0, Fortinet Antivirus 4.2.254.0, G Data AntiVirus 21, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Jiangmin Antivirus 13.0.900, K7 AntiVirus 9.77.3565, Kaspersky Anti-Virus 7.0.0.125, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwasher) 2010.1C, Antimalware Engine 1.1.6402.0 in Microsoft Security Essentials 2.0, NOD32 Antivirus 5795, Norman Antivirus 6.06.12, nProtect Anti-Virus 2011-01-17.01, Panda Antivirus 10.0.2.7, PC Tools AntiVirus 7.0.3.5, Rising Antivirus 22.83.00.03, Sophos Anti-Virus 4.61.0, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Trend Micro AntiVirus 9.120.0.1004, Trend Micro HouseCall 9.120.0.1004, VBA32 3.12.14.2, and VirusBuster 13.6.151.0 allows remote attackers to bypass malware detection via a TAR archive entry with a length field corresponding to that entire entry, plus part of the header of the next entry. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
emsisoft anti-malware 5.1.0.1
k7computing antivirus 9.77.3565
f-secure f-secure_anti-virus 9.0.16160.0
avg avg_anti-virus 10.0.0.1190
authentium command_antivirus 5.2.11.5
microsoft security_essentials 2.0
f-prot f-prot_antivirus 4.6.2.117
fortinet fortinet_antivirus 4.2.254.0
trendmicro trend_micro_antivirus 9.120.0.1004
mcafee gateway 2010.1c
ahnlab v3_internet_security 2011.01.18.00
pc_tools pc_tools_antivirus 7.0.3.5
jiangmin jiangmin_antivirus 13.0.900
bitdefender bitdefender 7.2
mcafee scan_engine 5.400.0.1158
eset nod32_antivirus 5795
norman norman_antivirus_&_antispyware 6.06.12
trendmicro housecall 9.120.0.1004
nprotect nprotect_antivirus 2011-01-17.01
ikarus ikarus_virus_utilities_t3_command_line_scanner 1.1.97.0
anti-virus vba32 3.12.14.2
symantec endpoint_protection 11.0
gdata-software g_data_antivirus 21
sophos sophos_anti-virus 4.61.0
avira antivir 7.11.1.163
cat quick_heal 11.00
alwil avast_antivirus 4.8.1351.0
rising-global rising_antivirus 22.83.00.03
clamav clamav 0.96.4
alwil avast_antivirus 5.0.677.0
comodo comodo_antivirus 7424
virusbuster virusbuster 13.6.151.0
antiy avl_sdk 2.0.3.7
pandasecurity panda_antivirus 10.0.2.7
kaspersky kaspersky_anti-virus 7.0.0.125
CVE-2012-1461 MEDIUM

The Gzip file parser in AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Command Antivirus 5.2.11.5, Emsisoft Anti-Malware 5.1.0.1, F-Secure Anti-Virus 9.0.16160.0, Fortinet Antivirus 4.2.254.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Jiangmin Antivirus 13.0.900, K7 AntiVirus 9.77.3565, Kaspersky Anti-Virus 7.0.0.125, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwasher) 2010.1C, NOD32 Antivirus 5795, Norman Antivirus 6.06.12, Rising Antivirus 22.83.00.03, Sophos Anti-Virus 4.61.0, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Trend Micro AntiVirus 9.120.0.1004, Trend Micro HouseCall 9.120.0.1004, and VBA32 3.12.14.2 allows remote attackers to bypass malware detection via a .tar.gz file with multiple compressed streams. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different Gzip parser implementations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
ikarus ikarus_virus_utilities_t3_command_line_scanner 1.1.97.0
anti-virus vba32 3.12.14.2
emsisoft anti-malware 5.1.0.1
symantec endpoint_protection 11.0
k7computing antivirus 9.77.3565
f-secure f-secure_anti-virus 9.0.16160.0
avg avg_anti-virus 10.0.0.1190
sophos sophos_anti-virus 4.61.0
authentium command_antivirus 5.2.11.5
fortinet fortinet_antivirus 4.2.254.0
trendmicro trend_micro_antivirus 9.120.0.1004
rising-global rising_antivirus 22.83.00.03
mcafee gateway 2010.1c
jiangmin jiangmin_antivirus 13.0.900
bitdefender bitdefender 7.2
mcafee scan_engine 5.400.0.1158
eset nod32_antivirus 5795
norman norman_antivirus_&_antispyware 6.06.12
trendmicro housecall 9.120.0.1004
kaspersky kaspersky_anti-virus 7.0.0.125