CVE Vulnerabilities

CVE-2012-1458

Published: Mar 21, 2012 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The Microsoft CHM file parser in ClamAV 0.96.4 and Sophos Anti-Virus 4.61.0 allows remote attackers to bypass malware detection via a crafted reset interval in the LZXC header of a CHM file. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different CHM parser implementations.

Affected Software

NameVendorStart VersionEnd Version
ClamavClamav0.96.4 (including)0.96.4 (including)
Sophos_anti-virusSophos4.61.0 (including)4.61.0 (including)
ClamavUbuntuhardy*
ClamavUbuntulucid*
ClamavUbuntumaverick*
ClamavUbuntunatty*
ClamavUbuntuoneiric*
ClamavUbuntuprecise*
ClamavUbuntuupstream*

References