4.3
CVSSv2

CVE-2012-1461

Published: 21/03/2012 Updated: 06/11/2012
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

The Gzip file parser in AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Command Antivirus 5.2.11.5, Emsisoft Anti-Malware 5.1.0.1, F-Secure Anti-Virus 9.0.16160.0, Fortinet Antivirus 4.2.254.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Jiangmin Antivirus 13.0.900, K7 AntiVirus 9.77.3565, Kaspersky Anti-Virus 7.0.0.125, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwasher) 2010.1C, NOD32 Antivirus 5795, Norman Antivirus 6.06.12, Rising Antivirus 22.83.00.03, Sophos Anti-Virus 4.61.0, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Trend Micro AntiVirus 9.120.0.1004, Trend Micro HouseCall 9.120.0.1004, and VBA32 3.12.14.2 allows remote malicious users to bypass malware detection via a .tar.gz file with multiple compressed streams. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different Gzip parser implementations.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

avg avg anti-virus 10.0.0.1190

bitdefender bitdefender 7.2

k7computing antivirus 9.77.3565

kaspersky kaspersky anti-virus 7.0.0.125

trendmicro trend micro antivirus 9.120.0.1004

trendmicro housecall 9.120.0.1004

authentium command antivirus 5.2.11.5

emsisoft anti-malware 5.1.0.1

mcafee scan engine 5.400.0.1158

mcafee gateway 2010.1c

anti-virus vba32 3.12.14.2

ikarus ikarus virus utilities t3 command line scanner 1.1.97.0

jiangmin jiangmin antivirus 13.0.900

sophos sophos anti-virus 4.61.0

symantec endpoint protection 11.0

f-secure f-secure anti-virus 9.0.16160.0

fortinet fortinet antivirus 4.2.254.0

eset nod32 antivirus 5795

norman norman antivirus \\& antispyware 6.06.12

rising-global rising antivirus 22.83.00.03