CVE Vulnerabilities

CVE-2012-1458

Published: Mar 21, 2012 | Modified: Jan 18, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

The Microsoft CHM file parser in ClamAV 0.96.4 and Sophos Anti-Virus 4.61.0 allows remote attackers to bypass malware detection via a crafted reset interval in the LZXC header of a CHM file. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different CHM parser implementations.

Affected Software

Name Vendor Start Version End Version
Clamav Clamav 0.96.4 (including) 0.96.4 (including)
Sophos_anti-virus Sophos 4.61.0 (including) 4.61.0 (including)
Clamav Ubuntu hardy *
Clamav Ubuntu lucid *
Clamav Ubuntu maverick *
Clamav Ubuntu natty *
Clamav Ubuntu oneiric *
Clamav Ubuntu precise *
Clamav Ubuntu upstream *

References