4.3

CVE-2012-1446

The ELF file parser in Quick Heal (aka Cat QuickHeal) 11.00, McAfee Anti-Virus Scanning Engine 5.400.0.1158, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Norman Antivirus 6.06.12, eSafe 7.0.17.0, Kaspersky Anti-Virus 7.0.0.125, McAfee Gateway (formerly Webwasher) 2010.1C, Sophos Anti-Virus 4.61.0, CA eTrust Vet Antivirus 36.1.8511, Antiy Labs AVL SDK 2.0.3.7, PC Tools AntiVirus 7.0.3.5, Rising Antivirus 22.83.00.03, Fortinet Antivirus 4.2.254.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an ELF file with a modified encoding field.  NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different ELF parser implementations.

Data is provided by the National Vulnerability Database (NVD)
AladdinEsafe Version7.0.17.0
AntiyAvl Sdk Version2.0.3.7
CaEtrust Vet Antivirus Version36.1.8511
CatQuick Heal Version11.00
FortinetFortinet Antivirus Version4.2.254.0
KasperskyKaspersky Anti-virus Version7.0.0.125
McafeeGateway Version2010.1c
McafeeScan Engine Version5.400.0.1158
PandasecurityPanda Antivirus Version10.0.2.7
Pc ToolsPc Tools Antivirus Version7.0.3.5
Rising-globalRising Antivirus Version22.83.00.03
SophosSophos Anti-virus Version4.61.0
SymantecEndpoint Protection Version11.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 2.54% 0.848
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N