CVE-2012-1458
Estado: ModificadaMedia (4.3)—
The Microsoft CHM file parser in ClamAV 0.96.4 and Sophos Anti-Virus 4.61.0 allows remote attackers to bypass malware detection via a crafted reset interval in the LZXC header of a CHM file. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different CHM parser implementations.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N
- Puntuación base: 4.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 74%
- Percentil entre todas las CVEs puntuadas: 99
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (2)
CWE
- CWE-264
Referencias
- http://lists.opensuse.org/opensuse-security-announce/2012-07/msg00002.html
- http://osvdb.org/80473
- http://osvdb.org/80474
- http://www.ieee-security.org/TC/SP2012/program.html
- http://www.mandriva.com/security/advisories?name=MDVSA-2012:094
- http://www.securityfocus.com/archive/1/522005
- http://www.securityfocus.com/bid/52611
- https://exchange.xforce.ibmcloud.com/vulnerabilities/74301
- http://lists.opensuse.org/opensuse-security-announce/2012-07/msg00002.html
- http://osvdb.org/80473
- http://osvdb.org/80474
- http://www.ieee-security.org/TC/SP2012/program.html
- http://www.mandriva.com/security/advisories?name=MDVSA-2012:094
- http://www.securityfocus.com/archive/1/522005
- http://www.securityfocus.com/bid/52611
- https://exchange.xforce.ibmcloud.com/vulnerabilities/74301
JSON original (NVD)
Mostrar
{
"id": "CVE-2012-1458",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4.3,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "MEDIUM",
"availabilityImpact": "NONE",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2012-03-21T10:11:49.317",
"references": [
{
"url": "http://lists.opensuse.org/opensuse-security-announce/2012-07/msg00002.html",
"source": "cve@mitre.org"
},
{
"url": "http://osvdb.org/80473",
"source": "cve@mitre.org"
},
{
"url": "http://osvdb.org/80474",
"source": "cve@mitre.org"
},
{
"url": "http://www.ieee-security.org/TC/SP2012/program.html",
"source": "cve@mitre.org"
},
{
"url": "http://www.mandriva.com/security/advisories?name=MDVSA-2012:094",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/522005",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/52611",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/74301",
"source": "cve@mitre.org"
},
{
"url": "http://lists.opensuse.org/opensuse-security-announce/2012-07/msg00002.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://osvdb.org/80473",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://osvdb.org/80474",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.ieee-security.org/TC/SP2012/program.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.mandriva.com/security/advisories?name=MDVSA-2012:094",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/522005",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/52611",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/74301",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-264"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The Microsoft CHM file parser in ClamAV 0.96.4 and Sophos Anti-Virus 4.61.0 allows remote attackers to bypass malware detection via a crafted reset interval in the LZXC header of a CHM file. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different CHM parser implementations."
},
{
"lang": "es",
"value": "El analizador de archivos CHM de Microsoft en ClamAV v0.96.4 y Sophos Anti-Virus v4.61.0 permite a atacantes remotos evitar la detección de malware a través de un intervalo de restablecimiento manipulado en la cabecera LZXC de un archivo CHM. NOTA: esto más adelante se puede dividir en varios CVEs si la información adicional que se publica muestra que el error se produjo de forma independiente en diferentes implementaciones del analizador de CHM."
}
],
"lastModified": "2026-06-16T23:39:34.273",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:clamav:clamav:0.96.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "953C363B-AD5B-4C53-AAF0-AB6BA4040D74"
},
{
"criteria": "cpe:2.3:a:sophos:sophos_anti-virus:4.61.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0912E21E-1EEB-4ADD-958F-F8AEBBF7C5E6"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}