4.3

CVE-2012-1460

The Gzip file parser in Antiy Labs AVL SDK 2.0.3.7, Quick Heal (aka Cat QuickHeal) 11.00, Command Antivirus 5.2.11.5, eSafe 7.0.17.0, F-Prot Antivirus 4.6.2.117, Jiangmin Antivirus 13.0.900, K7 AntiVirus 9.77.3565, and VBA32 3.12.14.2 allows remote attackers to bypass malware detection via a .tar.gz file with stray bytes at the end. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different Gzip parser implementations.

Data is provided by the National Vulnerability Database (NVD)
AladdinEsafe Version7.0.17.0
Anti-virusVba32 Version3.12.14.2
AntiyAvl Sdk Version2.0.3.7
AuthentiumCommand Antivirus Version5.2.11.5
CatQuick Heal Version11.00
F-protF-prot Antivirus Version4.6.2.117
JiangminJiangmin Antivirus Version13.0.900
K7computingAntivirus Version9.77.3565
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.57% 0.676
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N