This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Detail
Vendor Avira First view 2007-05-08
Product Antivir Last view 2012-03-21
Version Type Application
Update  
Edition  
Language  
Sofware Edition  
Target Software  
Target Hardware  
Other  

Activity : Overall

COMMON PLATFORM ENUMERATION: Repartition per Version

CPE Name Affected CVE
cpe:2.3:a:avira:antivir:*:*:*:*:*:*:*:* 5
cpe:2.3:a:avira:antivir:6.35.00.00:*:*:*:*:*:*:* 5
cpe:2.3:a:avira:antivir:-:-:premium:*:*:*:*:* 5
cpe:2.3:a:avira:antivir:7.04.00.23:*:*:*:*:*:*:* 4
cpe:2.3:a:avira:antivir:*:*:professional:*:*:*:*:* 4
cpe:2.3:a:avira:antivir:7.11.1.163:*:*:*:*:*:*:* 4

Related : CVE

  Date Alert Description
4.3 2012-03-21 CVE-2012-1459

The TAR file parser in AhnLab V3 Internet Security 2011.01.18.00, Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8.1351.0 and 5.0.677.0, AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Quick Heal (aka Cat QuickHeal) 11.00, ClamAV 0.96.4, Command Antivirus 5.2.11.5, Comodo Antivirus 7424, Emsisoft Anti-Malware 5.1.0.1, F-Prot Antivirus 4.6.2.117, F-Secure Anti-Virus 9.0.16160.0, Fortinet Antivirus 4.2.254.0, G Data AntiVirus 21, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Jiangmin Antivirus 13.0.900, K7 AntiVirus 9.77.3565, Kaspersky Anti-Virus 7.0.0.125, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwasher) 2010.1C, Antimalware Engine 1.1.6402.0 in Microsoft Security Essentials 2.0, NOD32 Antivirus 5795, Norman Antivirus 6.06.12, nProtect Anti-Virus 2011-01-17.01, Panda Antivirus 10.0.2.7, PC Tools AntiVirus 7.0.3.5, Rising Antivirus 22.83.00.03, Sophos Anti-Virus 4.61.0, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Trend Micro AntiVirus 9.120.0.1004, Trend Micro HouseCall 9.120.0.1004, VBA32 3.12.14.2, and VirusBuster 13.6.151.0 allows remote attackers to bypass malware detection via a TAR archive entry with a length field corresponding to that entire entry, plus part of the header of the next entry. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.

4.3 2012-03-21 CVE-2012-1457

The TAR file parser in Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8.1351.0 and 5.0.677.0, AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Quick Heal (aka Cat QuickHeal) 11.00, ClamAV 0.96.4, Command Antivirus 5.2.11.5, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, F-Prot Antivirus 4.6.2.117, G Data AntiVirus 21, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Jiangmin Antivirus 13.0.900, K7 AntiVirus 9.77.3565, Kaspersky Anti-Virus 7.0.0.125, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwasher) 2010.1C, Antimalware Engine 1.1.6402.0 in Microsoft Security Essentials 2.0, NOD32 Antivirus 5795, Norman Antivirus 6.06.12, PC Tools AntiVirus 7.0.3.5, Rising Antivirus 22.83.00.03, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Trend Micro AntiVirus 9.120.0.1004, Trend Micro HouseCall 9.120.0.1004, VBA32 3.12.14.2, and VirusBuster 13.6.151.0 allows remote attackers to bypass malware detection via a TAR archive entry with a length field that exceeds the total TAR file size. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.

4.3 2012-03-21 CVE-2012-1443

The RAR file parser in ClamAV 0.96.4, Rising Antivirus 22.83.00.03, Quick Heal (aka Cat QuickHeal) 11.00, G Data AntiVirus 21, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Command Antivirus 5.2.11.5, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Emsisoft Anti-Malware 5.1.0.1, PC Tools AntiVirus 7.0.3.5, F-Prot Antivirus 4.6.2.117, VirusBuster 13.6.151.0, Fortinet Antivirus 4.2.254.0, Antiy Labs AVL SDK 2.0.3.7, K7 AntiVirus 9.77.3565, Trend Micro HouseCall 9.120.0.1004, Kaspersky Anti-Virus 7.0.0.125, Jiangmin Antivirus 13.0.900, Antimalware Engine 1.1.6402.0 in Microsoft Security Essentials 2.0, Sophos Anti-Virus 4.61.0, NOD32 Antivirus 5795, Avira AntiVir 7.11.1.163, Norman Antivirus 6.06.12, McAfee Anti-Virus Scanning Engine 5.400.0.1158, Panda Antivirus 10.0.2.7, McAfee Gateway (formerly Webwasher) 2010.1C, Trend Micro AntiVirus 9.120.0.1004, Comodo Antivirus 7424, Bitdefender 7.2, eSafe 7.0.17.0, F-Secure Anti-Virus 9.0.16160.0, nProtect Anti-Virus 2011-01-17.01, AhnLab V3 Internet Security 2011.01.18.00, AVG Anti-Virus 10.0.0.1190, avast! Antivirus 4.8.1351.0 and 5.0.677.0, and VBA32 3.12.14.2 allows user-assisted remote attackers to bypass malware detection via a RAR file with an initial MZ character sequence. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different RAR parser implementations.

4.3 2012-03-21 CVE-2012-1425

The TAR file parser in Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, Quick Heal (aka Cat QuickHeal) 11.00, Emsisoft Anti-Malware 5.1.0.1, Fortinet Antivirus 4.2.254.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Jiangmin Antivirus 13.0.900, Kaspersky Anti-Virus 7.0.0.125, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwasher) 2010.1C, NOD32 Antivirus 5795, Norman Antivirus 6.06.12, PC Tools AntiVirus 7.0.3.5, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Trend Micro AntiVirus 9.120.0.1004, and Trend Micro HouseCall 9.120.0.1004 allows remote attackers to bypass malware detection via a POSIX TAR file with an initial \50\4B\03\04 character sequence. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.

7.2 2009-08-13 CVE-2009-2761

Unquoted Windows search path vulnerability in the scheduler (sched.exe) in Avira AntiVir, AntiVir Premium, Premium Security Suite, and AntiVir Professional might allow local users to gain privileges via a malicious antivir.exe file in the "C:\Program Files\avira\" directory.

7.2 2009-08-13 CVE-2008-6962

Avira AntiVir Premium, Premium Security Suite, AntiVir Professional, and AntiVir Personal - FREE allows local users to execute arbitrary code via a crafted IOCTL request that overwrites a kernel pointer.

10 2007-05-31 CVE-2007-2974

Buffer overflow in the file parsing engine in Avira Antivir Antivirus before 7.03.00.09 allows remote attackers to execute arbitrary code via a crafted LZH archive file, resulting from an "integer cast around."

7.8 2007-05-31 CVE-2007-2973

Avira Antivir Antivirus before 7.03.00.09 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a malformed TAR archive.

7.8 2007-05-31 CVE-2007-2972

The file parsing engine in Avira Antivir Antivirus before 7.04.00.24 allows remote attackers to cause a denial of service (application crash) via a crafted UPX compressed file, which triggers a divide-by-zero error.

7.8 2007-05-08 CVE-2007-1673

unzoo.c, as used in multiple products including AMaViS 2.4.1 and earlier, allows remote attackers to cause a denial of service (infinite loop) via a ZOO archive with a direntry structure that points to a previous file.

CWE : Common Weakness Enumeration

%idName
66% (4) CWE-264 Permissions, Privileges, and Access Controls
16% (1) CWE-399 Resource Management Errors
16% (1) CWE-20 Improper Input Validation

Open Source Vulnerability Database (OSVDB)

id Description
57004 Avira Antivir Multiple Products Crafted IOCTL Request Arbitrary Local Code Ex...
55647 Avira Multiple Products sched.exe CreateProcess() API Local Privilege Escalation
37302 zoo Decoder unzoo.c Malformed Zoo Archive Handling DoS
36712 Avira AntiVir Antivirus LZH Archive Handling Overflow
36711 Avira AntiVir Antivirus TAR Archive Handling DoS
36710 Avira AntiVir Antivirus UPX File Handling DoS
36208 unzoo ZOO Archive Malformed direntry Structure DoS

OpenVAS Exploits

id Description
2012-12-13 Name : SuSE Update for ClamAV openSUSE-SU-2012:0833-1 (ClamAV)
File : nvt/gb_suse_2012_0833_1.nasl
2012-08-30 Name : Fedora Update for clamav FEDORA-2012-9563
File : nvt/gb_fedora_2012_9563_clamav_fc17.nasl
2012-08-17 Name : Ubuntu Update for clamav USN-1482-3
File : nvt/gb_ubuntu_USN_1482_3.nasl
2012-08-10 Name : FreeBSD Ports: clamav
File : nvt/freebsd_clamav17.nasl
2012-07-16 Name : Fedora Update for clamav FEDORA-2012-9577
File : nvt/gb_fedora_2012_9577_clamav_fc16.nasl
2012-06-22 Name : Ubuntu Update for clamav USN-1482-1
File : nvt/gb_ubuntu_USN_1482_1.nasl
2012-06-22 Name : Ubuntu Update for clamav USN-1482-2
File : nvt/gb_ubuntu_USN_1482_2.nasl

Snort® IPS/IDS

Date Description
2019-08-31 TAR multiple antivirus evasion attempt
RuleID : 50838 - Type : FILE-OTHER - Revision : 1
2017-10-10 RAR file malformed header antivirus evasion attempt
RuleID : 44323 - Type : FILE-OTHER - Revision : 2
2014-06-14 possible TAR file oversize length field
RuleID : 30995 - Type : INDICATOR-COMPROMISE - Revision : 2
2014-06-14 possible TAR file oversize length field
RuleID : 30994 - Type : INDICATOR-COMPROMISE - Revision : 2
2014-01-10 TAR multiple antivirus evasion attempt
RuleID : 23325 - Type : FILE-OTHER - Revision : 5

Nessus® Vulnerability Scanner

id Description
2014-06-13 Name: The remote openSUSE host is missing a security update.
File: openSUSE-2012-362.nasl - Type: ACT_GATHER_INFO
2013-01-25 Name: The remote SuSE 11 host is missing a security update.
File: suse_11_clamav-120622.nasl - Type: ACT_GATHER_INFO
2012-08-17 Name: The remote Ubuntu host is missing one or more security-related patches.
File: ubuntu_USN-1482-3.nasl - Type: ACT_GATHER_INFO
2012-07-11 Name: The remote Fedora host is missing a security update.
File: fedora_2012-9577.nasl - Type: ACT_GATHER_INFO
2012-07-11 Name: The remote SuSE 10 host is missing a security-related patch.
File: suse_clamav-8200.nasl - Type: ACT_GATHER_INFO
2012-06-27 Name: The remote antivirus service is affected by multiple vulnerabilities.
File: clamav_0_97_5.nasl - Type: ACT_GATHER_INFO
2012-06-25 Name: The remote Fedora host is missing a security update.
File: fedora_2012-9563.nasl - Type: ACT_GATHER_INFO
2012-06-20 Name: The remote Ubuntu host is missing one or more security-related patches.
File: ubuntu_USN-1482-1.nasl - Type: ACT_GATHER_INFO
2012-06-20 Name: The remote Ubuntu host is missing one or more security-related patches.
File: ubuntu_USN-1482-2.nasl - Type: ACT_GATHER_INFO
2012-06-18 Name: The remote FreeBSD host is missing one or more security-related updates.
File: freebsd_pkg_eb12ebeeb7af11e1b5e0000c299b62e1.nasl - Type: ACT_GATHER_INFO
2007-05-31 Name: The remote Windows host contains an application that is affected by multiple ...
File: avira_file_vulns.nasl - Type: ACT_GATHER_INFO