The CAB file parser in Dr.Web 5.0.2.03300, Trend Micro HouseCall...
Vulnerability Description
The CAB file parser in Dr.Web 5.0.2.03300, Trend Micro HouseCall 9.120.0.1004, Kaspersky Anti-Virus 7.0.0.125, Sophos Anti-Virus 4.61.0, Trend Micro AntiVirus 9.120.0.1004, McAfee Gateway (formerly Webwasher) 2010.1C, Emsisoft Anti-Malware 5.1.0.1, CA eTrust Vet Antivirus 36.1.8511, Antiy Labs AVL SDK 2.0.3.7, Antimalware Engine 1.1.6402.0 in Microsoft Security Essentials 2.0, Rising Antivirus 22.83.00.03, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Fortinet Antivirus 4.2.254.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via a CAB file with a modified coffFiles field. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different CAB parser implementations.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2012-1453
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.securityfocus.com/archive/1/522005
- http://osvdb.org/80487
- http://osvdb.org/80484
- http://osvdb.org/80482
- http://osvdb.org/80489
- http://osvdb.org/80488
- http://www.ieee-security.org/TC/SP2012/program.html
- http://osvdb.org/80486
- http://www.securityfocus.com/bid/52621
- http://osvdb.org/80483
- http://osvdb.org/80485
More from antiy
View All →Affected Vendor
antiy
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.