CVE-2012-1443
published 2012-03-21CVE-2012-1443: The RAR file parser in ClamAV 0.96.4, Rising Antivirus 22.83.00.03, Quick Heal (aka Cat QuickHeal) 11.00, G Data AntiVirus 21, AVEngine 20101.3.0.103 in…
PriorityP342medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
99.64%
99.9th percentile
The RAR file parser in ClamAV 0.96.4, Rising Antivirus 22.83.00.03, Quick Heal (aka Cat QuickHeal) 11.00, G Data AntiVirus 21, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Command Antivirus 5.2.11.5, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Emsisoft Anti-Malware 5.1.0.1, PC Tools AntiVirus 7.0.3.5, F-Prot Antivirus 4.6.2.117, VirusBuster 13.6.151.0, Fortinet Antivirus 4.2.254.0, Antiy Labs AVL SDK 2.0.3.7, K7 AntiVirus 9.77.3565, Trend Micro HouseCall 9.120.0.1004, Kaspersky Anti-Virus 7.0.0.125, Jiangmin Antivirus 13.0.900, Antimalware Engine 1.1.6402.0 in Microsoft Security Essentials 2.0, Sophos Anti-Virus 4.61.0, NOD32 Antivirus 5795, Avira AntiVir 7.11.1.163, Norman Antivirus 6.06.12, McAfee Anti-Virus Scanning Engine 5.400.0.1158, Panda Antivirus 10.0.2.7, McAfee Gateway (formerly Webwasher) 2010.1C, Trend Micro AntiVirus 9.120.0.1004, Comodo Antivirus 7424, Bitdefender 7.2, eSafe 7.0.17.0, F-Secure Anti-Virus 9.0.16160.0, nProtect Anti-Virus 2011-01-17.01, AhnLab V3 Internet Security 2011.01.18.00, AVG Anti-Virus 10.0.0.1190, avast! Antivirus 4.8.1351.0 and 5.0.677.0, and VBA32 3.12.14.2 allows user-assisted remote attackers to bypass malware detection via a RAR file with an initial MZ character sequence. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different RAR parser implementations.
Affected
36 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ahnlab | v3_internet_security | — | — |
| aladdin | esafe | — | — |
| alwil | avast_antivirus | — | — |
| alwil | avast_antivirus | — | — |
| anti-virus | vba32 | — | — |
| antiy | avl_sdk | — | — |
| authentium | command_antivirus | — | — |
| avg | avg_anti-virus | — | — |
| avira | antivir | — | — |
| bitdefender | bitdefender | — | — |
| cat | quick_heal | — | — |
| clamav | clamav | — | — |
| comodo | comodo_antivirus | — | — |
| emsisoft | anti-malware | — | — |
| eset | nod32_antivirus | — | — |
| f-prot | f-prot_antivirus | — | — |
| f-secure | f-secure_anti-virus | — | — |
| fortinet | fortinet_antivirus | — | — |
| gdata-software | g_data_antivirus | — | — |
| ikarus | ikarus_virus_utilities_t3_command_line_scanner | — | — |
| jiangmin | jiangmin_antivirus | — | — |
| k7computing | antivirus | — | — |
| kaspersky | kaspersky_anti-virus | — | — |
| mcafee | gateway | — | — |
| mcafee | scan_engine | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →A RAR file with an initial MZ character sequence (MZ magic bytes at the start of a RAR archive) can be used to bypass malware detection in vulnerable AV RAR parsers ↗
- →Inspect RAR file parsing logic for files whose first two bytes are 'MZ' (0x4D 0x5A) — such files should still be parsed as RAR archives and not misidentified or skipped based on the MZ magic bytes ↗
- ·The flaw was reported against ClamAV 0.96.4; it was unknown at the time of the Red Hat bug whether the flaw persisted in later versions, but was confirmed fixed in ClamAV 0.97.5 ↗
- ·The CVE may later be split into multiple CVEs if the RAR parser error is shown to have occurred independently across the many affected AV products listed ↗
- ·These CVEs were corrected in ClamAV 0.97.5 ↗
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-1443 clamav: specially-crafted RAR files evade detection
bugzilla·2012-03-22·CVSS 4.3
CVE-2012-1443 [MEDIUM] CVE-2012-1443 clamav: specially-crafted RAR files evade detection
CVE-2012-1443 clamav: specially-crafted RAR files evade detection
Common Vulnerabilities and Exposures assigned an identifier CVE-2012-1443 to
the following vulnerability:
Name: CVE-2012-1443
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1443
Assigned: 20120229
Reference: BUGTRAQ:20120319 Evasion attacks expoliting file-parsing vulnerabilities in antivirus products
Reference: http://www.securityfocus.com/archive/1/522005
Reference: http://www.ieee-security.org/TC/SP2012/program.html
The RAR file parser in ClamAV 0.96.4, Rising Antivirus 22.83.00.03,
Quick Heal (aka Cat QuickHeal) 11.00, G Data AntiVirus 21, AVEngine
20101.3.0.103 in Symantec Endpoint Protection 11, Command Antivirus
5.2.11.5, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0,
Emsisoft Anti-Malware 5.
Bugzilla
CVE-2012-1419 CVE-2012-1443 CVE-2012-1457 CVE-2012-1458 CVE-2012-1459 clamav various flaws [epel-all]
bugzilla·2012-03-22·CVSS 4.3
CVE-2012-1419 [MEDIUM] CVE-2012-1419 CVE-2012-1443 CVE-2012-1457 CVE-2012-1458 CVE-2012-1459 clamav various flaws [epel-all]
CVE-2012-1419 CVE-2012-1443 CVE-2012-1457 CVE-2012-1458 CVE-2012-1459 clamav various flaws [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/u
Bugzilla
CVE-2012-1419 CVE-2012-1443 CVE-2012-1457 CVE-2012-1458 CVE-2012-1459 clamav various flaws [fedora-all]
bugzilla·2012-03-22·CVSS 4.3
CVE-2012-1419 [MEDIUM] CVE-2012-1419 CVE-2012-1443 CVE-2012-1457 CVE-2012-1458 CVE-2012-1459 clamav various flaws [fedora-all]
CVE-2012-1419 CVE-2012-1443 CVE-2012-1457 CVE-2012-1458 CVE-2012-1459 clamav various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org
http://osvdb.org/80454http://osvdb.org/80455http://osvdb.org/80456http://osvdb.org/80457http://osvdb.org/80458http://osvdb.org/80459http://osvdb.org/80460http://osvdb.org/80461http://osvdb.org/80467http://osvdb.org/80468http://osvdb.org/80469http://osvdb.org/80470http://osvdb.org/80471http://osvdb.org/80472http://www.ieee-security.org/TC/SP2012/program.htmlhttp://www.securityfocus.com/archive/1/522005http://www.securityfocus.com/bid/52612http://osvdb.org/80454http://osvdb.org/80455http://osvdb.org/80456http://osvdb.org/80457http://osvdb.org/80458http://osvdb.org/80459http://osvdb.org/80460http://osvdb.org/80461http://osvdb.org/80467http://osvdb.org/80468http://osvdb.org/80469http://osvdb.org/80470http://osvdb.org/80471http://osvdb.org/80472http://www.ieee-security.org/TC/SP2012/program.htmlhttp://www.securityfocus.com/archive/1/522005http://www.securityfocus.com/bid/52612
2012-03-21
Published