4.3

CVE-2012-1453

The CAB file parser in Dr.Web 5.0.2.03300, Trend Micro HouseCall 9.120.0.1004, Kaspersky Anti-Virus 7.0.0.125, Sophos Anti-Virus 4.61.0, Trend Micro AntiVirus 9.120.0.1004, McAfee Gateway (formerly Webwasher) 2010.1C, Emsisoft Anti-Malware 5.1.0.1, CA eTrust Vet Antivirus 36.1.8511, Antiy Labs AVL SDK 2.0.3.7, Antimalware Engine 1.1.6402.0 in Microsoft Security Essentials 2.0, Rising Antivirus 22.83.00.03, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Fortinet Antivirus 4.2.254.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via a CAB file with a modified coffFiles field.  NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different CAB parser implementations.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Antiy ≫ Avl Sdk Version 2.0.3.7
Ca ≫ Etrust Vet Antivirus Version 36.1.8511
Drweb ≫ Dr.Web Antivirus Version 5.0.2.03300
Emsisoft ≫ Anti-malware Version 5.1.0.1
Fortinet ≫ Fortinet Antivirus Version 4.2.254.0
Kaspersky ≫ Kaspersky Anti-virus Version 7.0.0.125
Mcafee ≫ Gateway Version 2010.1c
Microsoft ≫ Security Essentials Version 2.0
Pandasecurity ≫ Panda Antivirus Version 10.0.2.7
Rising-global ≫ Rising Antivirus Version 22.83.00.03
Sophos ≫ Sophos Anti-virus Version 4.61.0
Trendmicro ≫ Housecall Version 9.120.0.1004
Trendmicro ≫ Trend Micro Antivirus Version 9.120.0.1004
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 97.71% 0.999
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://www.ieee-security.org/TC/SP2012/program.html
http://www.securityfocus.com/archive/1/522005
http://osvdb.org/80482
http://osvdb.org/80483
http://osvdb.org/80484
http://osvdb.org/80485
http://osvdb.org/80486
http://osvdb.org/80487
http://osvdb.org/80488
http://osvdb.org/80489
http://www.securityfocus.com/bid/52621