CVE-2012-1446

N/A Unknown
Published: March 21, 2012 Modified: April 29, 2026
View on NVD

Description

The ELF file parser in Quick Heal (aka Cat QuickHeal) 11.00, McAfee Anti-Virus Scanning Engine 5.400.0.1158, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Norman Antivirus 6.06.12, eSafe 7.0.17.0, Kaspersky Anti-Virus 7.0.0.125, McAfee Gateway (formerly Webwasher) 2010.1C, Sophos Anti-Virus 4.61.0, CA eTrust Vet Antivirus 36.1.8511, Antiy Labs AVL SDK 2.0.3.7, PC Tools AntiVirus 7.0.3.5, Rising Antivirus 22.83.00.03, Fortinet Antivirus 4.2.254.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an ELF file with a modified encoding field. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different ELF parser implementations.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://osvdb.org/80426
Source: cve@mitre.org
http://osvdb.org/80427
Source: cve@mitre.org
http://osvdb.org/80428
Source: cve@mitre.org
http://osvdb.org/80430
Source: cve@mitre.org
http://osvdb.org/80431
Source: cve@mitre.org
http://osvdb.org/80426
Source: af854a3a-2127-422b-91ae-364da2661108
http://osvdb.org/80427
Source: af854a3a-2127-422b-91ae-364da2661108
http://osvdb.org/80428
Source: af854a3a-2127-422b-91ae-364da2661108
http://osvdb.org/80430
Source: af854a3a-2127-422b-91ae-364da2661108
http://osvdb.org/80431
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.ieee-security.org/TC/SP2012/program.html
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/archive/1/522005
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/bid/52600
Source: af854a3a-2127-422b-91ae-364da2661108

16 reference(s) from NVD

Quick Stats

CVSS v3 Score
N/A / 10.0
EPSS (Exploit Probability)
99.7%
100th percentile
Exploitation Status
Not in CISA KEV

Weaknesses (CWE)

Affected Vendors

cat symantec ca aladdin fortinet mcafee norman antiy pandasecurity pc_tools +3 more