Description
The Gzip file parser in AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Command Antivirus 5.2.11.5, Emsisoft Anti-Malware 5.1.0.1, F-Secure Anti-Virus 9.0.16160.0, Fortinet Antivirus 4.2.254.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Jiangmin Antivirus 13.0.900, K7 AntiVirus 9.77.3565, Kaspersky Anti-Virus 7.0.0.125, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwasher) 2010.1C, NOD32 Antivirus 5795, Norman Antivirus 6.06.12, Rising Antivirus 22.83.00.03, Sophos Anti-Virus 4.61.0, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Trend Micro AntiVirus 9.120.0.1004, Trend Micro HouseCall 9.120.0.1004, and VBA32 3.12.14.2 allows remote attackers to bypass malware detection via a .tar.gz file with multiple compressed streams. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different Gzip parser implementations.
Published: 2012-03-21
Score: 4.3 Medium
EPSS: 83.9% High
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

No history.

Subscriptions

Anti-virus Vba32
Authentium Command Antivirus
Avg Avg Anti-virus
Bitdefender Bitdefender
Emsisoft Anti-malware
Eset Nod32 Antivirus
F-secure F-secure Anti-virus
Fortinet Fortinet Antivirus
Ikarus Ikarus Virus Utilities T3 Command Line Scanner
Jiangmin Jiangmin Antivirus
K7computing Antivirus
Kaspersky Kaspersky Anti-virus
Mcafee Gateway Scan Engine
Norman Norman Antivirus \& Antispyware
Rising-global Rising Antivirus
Sophos Sophos Anti-virus
Symantec Endpoint Protection
Trendmicro Housecall Trend Micro Antivirus
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-06T19:01:01.258Z

Reserved: 2012-02-29T00:00:00.000Z

Link: CVE-2012-1461

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2012-03-21T10:11:49.677

Modified: 2026-04-29T01:13:23.040

Link: CVE-2012-1461

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses