CVE-2012-1426

CWE-2643 documents3 sources
Severity
4.3MEDIUM
EPSS
0.3%
top 42.54%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 21
Latest updateMay 17

Description

The TAR file parser in Quick Heal (aka Cat QuickHeal) 11.00, Command Antivirus 5.2.11.5, F-Prot Antivirus 4.6.2.117, K7 AntiVirus 9.77.3565, Norman Antivirus 6.06.12, and Rising Antivirus 22.83.00.03 allows remote attackers to bypass malware detection via a POSIX TAR file with an initial \42\5A\68 character sequence. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages6 packages

🔴Vulnerability Details

2
GHSA
GHSA-jx63-73f5-2r54: The TAR file parser in Quick Heal (aka Cat QuickHeal) 112022-05-17
CVEList
CVE-2012-1426: The TAR file parser in Quick Heal (aka Cat QuickHeal) 112012-03-21