CVE Vulnerabilities

CVE-2012-1419

Published: Mar 21, 2012 | Modified: Aug 14, 2012
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

The TAR file parser in ClamAV 0.96.4 and Quick Heal (aka Cat QuickHeal) 11.00 allows remote attackers to bypass malware detection via a POSIX TAR file with an initial [aliases] character sequence. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.

Affected Software

Name Vendor Start Version End Version
Quick_heal Cat 11.00 (including) 11.00 (including)
Clamav Clamav 0.96.4 (including) 0.96.4 (including)
Clamav Ubuntu maverick *
Clamav Ubuntu upstream *

References