MEDIUM · 4.3

CVE-2012-1452

The CAB file parser in Emsisoft Anti-Malware 5.1.0.1, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, and Quick Heal (aka Cat QuickHeal) 11.00 allows remote attackers to bypass malware detect...

Vulnerability Description

The CAB file parser in Emsisoft Anti-Malware 5.1.0.1, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, and Quick Heal (aka Cat QuickHeal) 11.00 allows remote attackers to bypass malware detection via a CAB file with a modified reserved1 field. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different CAB parser implementations.

CVSS Score

4.3

MEDIUM

AV:N/AC:M/Au:N/C:N/I:P/A:N
Confidentiality
NONE
Integrity
PARTIAL
Availability
NONE

Affected Products

VendorProductVersions
CatQuick Heal11.00
EmsisoftAnti-Malware5.1.0.1
IkarusIkarus Virus Utilities T3 Command Line Scanner1.1.97.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2012-1452?

CVE-2012-1452 is a vulnerability with a CVSS score of 4.3 (MEDIUM). The CAB file parser in Emsisoft Anti-Malware 5.1.0.1, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, and Quick Heal (aka Cat QuickHeal) 11.00 allows remote attackers to bypass malware detect...

How severe is CVE-2012-1452?

CVE-2012-1452 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2012-1452?

Check the references section above for vendor advisories and patch information. Affected products include: Cat Quick Heal, Emsisoft Anti-Malware, Ikarus Ikarus Virus Utilities T3 Command Line Scanner.