CVE-2012-1447
medium · 4.3The ELF file parser in Fortinet Antivirus 4.2.254.0, eSafe 7.0.17.0, Dr.Web 5.0.2.03300, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an ELF file with a modified e_version field. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different ELF parser implementations.
4.3
CVSS
67.7%
EPSS (exploit prob.)
99th
EPSS percentile
2012-03-21
Published
AV:N/AC:M/Au:N/C:N/I:P/A:N
Weaknesses
CWE-264
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| aladdin | esafe | 7.0.17.0 |
| drweb | dr.web_antivirus | 5.0.2.03300 |
| fortinet | fortinet_antivirus | 4.2.254.0 |
| pandasecurity | panda_antivirus | 10.0.2.7 |
Check a specific version with /api/v1/cve/match.
References
- http://osvdb.org/80432
- http://www.ieee-security.org/TC/SP2012/program.html
- http://www.securityfocus.com/archive/1/522005
- http://www.securityfocus.com/bid/52601
- http://osvdb.org/80432
- http://www.ieee-security.org/TC/SP2012/program.html
- http://www.securityfocus.com/archive/1/522005
- http://www.securityfocus.com/bid/52601
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2012-1447