cbcvebase.
CVE-2012-1443
published 2012-03-21

CVE-2012-1443: The RAR file parser in ClamAV 0.96.4, Rising Antivirus 22.83.00.03, Quick Heal (aka Cat QuickHeal) 11.00, G Data AntiVirus 21, AVEngine 20101.3.0.103 in…

PriorityP342medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
99.64%
99.9th percentile
The RAR file parser in ClamAV 0.96.4, Rising Antivirus 22.83.00.03, Quick Heal (aka Cat QuickHeal) 11.00, G Data AntiVirus 21, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Command Antivirus 5.2.11.5, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Emsisoft Anti-Malware 5.1.0.1, PC Tools AntiVirus 7.0.3.5, F-Prot Antivirus 4.6.2.117, VirusBuster 13.6.151.0, Fortinet Antivirus 4.2.254.0, Antiy Labs AVL SDK 2.0.3.7, K7 AntiVirus 9.77.3565, Trend Micro HouseCall 9.120.0.1004, Kaspersky Anti-Virus 7.0.0.125, Jiangmin Antivirus 13.0.900, Antimalware Engine 1.1.6402.0 in Microsoft Security Essentials 2.0, Sophos Anti-Virus 4.61.0, NOD32 Antivirus 5795, Avira AntiVir 7.11.1.163, Norman Antivirus 6.06.12, McAfee Anti-Virus Scanning Engine 5.400.0.1158, Panda Antivirus 10.0.2.7, McAfee Gateway (formerly Webwasher) 2010.1C, Trend Micro AntiVirus 9.120.0.1004, Comodo Antivirus 7424, Bitdefender 7.2, eSafe 7.0.17.0, F-Secure Anti-Virus 9.0.16160.0, nProtect Anti-Virus 2011-01-17.01, AhnLab V3 Internet Security 2011.01.18.00, AVG Anti-Virus 10.0.0.1190, avast! Antivirus 4.8.1351.0 and 5.0.677.0, and VBA32 3.12.14.2 allows user-assisted remote attackers to bypass malware detection via a RAR file with an initial MZ character sequence. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different RAR parser implementations.

Affected

36 ranges· showing 25
VendorProductVersion rangeFixed in
ahnlabv3_internet_security
aladdinesafe
alwilavast_antivirus
alwilavast_antivirus
anti-virusvba32
antiyavl_sdk
authentiumcommand_antivirus
avgavg_anti-virus
aviraantivir
bitdefenderbitdefender
catquick_heal
clamavclamav
comodocomodo_antivirus
emsisoftanti-malware
esetnod32_antivirus
f-protf-prot_antivirus
f-securef-secure_anti-virus
fortinetfortinet_antivirus
gdata-softwareg_data_antivirus
ikarusikarus_virus_utilities_t3_command_line_scanner
jiangminjiangmin_antivirus
k7computingantivirus
kasperskykaspersky_anti-virus
mcafeegateway
mcafeescan_engine

Detection & IOCsextracted from sources · hover to see the quote

  • A RAR file with an initial MZ character sequence (MZ magic bytes at the start of a RAR archive) can be used to bypass malware detection in vulnerable AV RAR parsers
  • Inspect RAR file parsing logic for files whose first two bytes are 'MZ' (0x4D 0x5A) — such files should still be parsed as RAR archives and not misidentified or skipped based on the MZ magic bytes
  • ·The flaw was reported against ClamAV 0.96.4; it was unknown at the time of the Red Hat bug whether the flaw persisted in later versions, but was confirmed fixed in ClamAV 0.97.5
  • ·The CVE may later be split into multiple CVEs if the RAR parser error is shown to have occurred independently across the many affected AV products listed
  • ·These CVEs were corrected in ClamAV 0.97.5
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.