CVE-2012-1454
Summary
| CVE | CVE-2012-1454 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2012-03-21 10:11:00 UTC |
| Updated | 2012-07-28 03:30:00 UTC |
| Description | The ELF file parser in Dr.Web 5.0.2.03300, eSafe 7.0.17.0, McAfee Gateway (formerly Webwasher) 2010.1C, Rising Antivirus 22.83.00.03, Fortinet Antivirus 4.2.254.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an ELF file with a modified ei_version field. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different ELF parser implementations. |
Risk And Classification
Problem Types: CWE-264
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Aladdin | Esafe | 7.0.17.0 | All | All | All |
| Application | Aladdin | Esafe | 7.0.17.0 | All | All | All |
| Application | Drweb | Dr.web Antivirus | 5.0.2.03300 | All | All | All |
| Application | Drweb | Dr.web Antivirus | 5.0.2.03300 | All | All | All |
| Application | Fortinet | Fortinet Antivirus | 4.2.254.0 | All | All | All |
| Application | Fortinet | Fortinet Antivirus | 4.2.254.0 | All | All | All |
| Application | Mcafee | Gateway | 2010.1c | All | All | All |
| Application | Mcafee | Gateway | 2010.1c | All | All | All |
| Application | Pandasecurity | Panda Antivirus | 10.0.2.7 | All | All | All |
| Application | Pandasecurity | Panda Antivirus | 10.0.2.7 | All | All | All |
| Application | Rising-global | Rising Antivirus | 22.83.00.03 | All | All | All |
| Application | Rising-global | Rising Antivirus | 22.83.00.03 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IEEE Symposium on Security and Privacy 2012 | MISC | www.ieee-security.org | |
| 80432 | OSVDB | osvdb.org | |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.