First published: Wed Mar 21 2012(Updated: )
The ELF file parser in Dr.Web 5.0.2.03300, eSafe 7.0.17.0, McAfee Gateway (formerly Webwasher) 2010.1C, Rising Antivirus 22.83.00.03, Fortinet Antivirus 4.2.254.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an ELF file with a modified ei_version field. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different ELF parser implementations.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Aladdin eSafe | =7.0.17.0 | |
Dr.Web Antivirus | =5.0.2.03300 | |
Fortinet Antivirus | =4.2.254.0 | |
McAfee Gateway | =2010.1c | |
Panda Security | =10.0.2.7 | |
Rising Antivirus | =22.83.00.03 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-1454 has a medium severity level due to its ability to bypass malware detection.
To fix CVE-2012-1454, update your antivirus software to the latest version provided by your vendor.
CVE-2012-1454 affects various antivirus solutions including Dr.Web, Fortinet Antivirus, and McAfee Gateway.
CVE-2012-1454 allows attackers to modify the ei_version field in ELF files to evade detection.
Yes, exploiting CVE-2012-1454 can potentially allow attackers to deliver malware without detection.