CVE-2012-1428: Medium severity quickheal cat quickheal vulnerability
The TAR file parser in Quick Heal (aka Cat QuickHeal) 11.00, Norman Antivirus 6.06.12, and Sophos Anti-Virus 4.61.0 allows remote attackers to bypass malware detection via a POSIX TAR file with a \4a\46\49\46 character sequence at a certain location. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-1428?
CVE-2012-1428 is classified as a vulnerability that allows remote attackers to bypass malware detection.
How do I fix CVE-2012-1428?
To fix CVE-2012-1428, users should update their Quick Heal, Norman Antivirus, or Sophos Anti-Virus software to the latest version provided by the vendors.
Which software is affected by CVE-2012-1428?
CVE-2012-1428 affects Quick Heal version 11.00, Norman Antivirus version 6.06.12, and Sophos Anti-Virus version 4.61.0.
What kind of attack does CVE-2012-1428 facilitate?
CVE-2012-1428 facilitates a situation where attackers can leverage a specific TAR file construct to evade detection by antivirus solutions.
Is there a known exploit for CVE-2012-1428?
Yes, CVE-2012-1428 describes a method for attackers to create a malicious TAR file that can evade detection by certain antivirus programs.