CVE-2012-1419: Medium severity quickheal cat quickheal vulnerability
The TAR file parser in ClamAV 0.96.4 and Quick Heal (aka Cat QuickHeal) 11.00 allows remote attackers to bypass malware detection via a POSIX TAR file with an initial [aliases] character sequence. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-1419?
The severity of CVE-2012-1419 is considered moderate as it allows for malware detection bypass.
How do I fix CVE-2012-1419?
To fix CVE-2012-1419, update ClamAV to a version newer than 0.96.4 and Quick Heal to a version beyond 11.00.
What products are affected by CVE-2012-1419?
CVE-2012-1419 affects ClamAV version 0.96.4 and Quick Heal version 11.00.
Can CVE-2012-1419 lead to remote code execution?
CVE-2012-1419 does not directly lead to remote code execution, but it can allow attackers to bypass malware detection.
Is CVE-2012-1419 related to file parsing vulnerabilities?
Yes, CVE-2012-1419 is related to vulnerabilities in the TAR file parser used by the affected software.