HomeAladdinCVE-2012-1460

CVE-2012-1460

UNKNOWN
4.3CVSS
Published: 2012-03-21
Updated: 2025-04-11
AI Analysis

Description

The Gzip file parser in Antiy Labs AVL SDK 2.0.3.7, Quick Heal (aka Cat QuickHeal) 11.00, Command Antivirus 5.2.11.5, eSafe 7.0.17.0, F-Prot Antivirus 4.6.2.117, Jiangmin Antivirus 13.0.900, K7 AntiVirus 9.77.3565, and VBA32 3.12.14.2 allows remote attackers to bypass malware detection via a .tar.gz file with stray bytes at the end. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different Gzip parser implementations.

CVSS Metrics

Vector
AV:N/AC:M/Au:N/C:N/I:P/A:N
Access Vector
network
Access Cmplx
medium
Auth
none
Confidentiality
none
Integrity
partial
Availability
none
Weaknesses
CWE-264

Metadata

Primary Vendor
ALADDIN
Published
3/21/2012
Last Modified
4/11/2025
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

aladdin : esafeanti-virus : vba32antiy : avl_sdkauthentium : command_antiviruscat : quick_healf-prot : f-prot_antivirusjiangmin : jiangmin_antivirusk7computing : antivirus

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief