CVE-2012-1458
EPSS 73.7%
描述
The Microsoft CHM file parser in ClamAV 0.96.4 and Sophos Anti-Virus 4.61.0 allows remote attackers to bypass malware detection via a crafted reset interval in the LZXC header of a CHM file. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different CHM parser implementations.
如何修補 CVE-2012-1458
要修補 CVE-2012-1458,請將受影響套件升級到下列已修補版本。
- Debian/clamav—升級至 0.97.5+dfsg-1 或更新版本
CVE-2012-1458 正在被利用嗎?
可能 — EPSS 為 73.7%,屬於高被利用機率區間,建議優先修補。
受影響套件(1)
- from 0, < 0.97.5+dfsg-1